Bug 2141496 (CVE-2022-41742) - CVE-2022-41742 nginx: Memory disclosure in the ngx_http_mp4_module
Summary: CVE-2022-41742 nginx: Memory disclosure in the ngx_http_mp4_module
Keywords:
Status: NEW
Alias: CVE-2022-41742
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2148866 2141497 2141498 2141499 2141500 2141501 2141502 2141503 2141504 2141505 2141513 2141515
Blocks: 2136367
TreeView+ depends on / blocked
 
Reported: 2022-11-10 04:53 UTC by Sandipan Roy
Modified: 2025-05-15 08:28 UTC (History)
46 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:7402 0 None None None 2025-05-13 11:52:50 UTC
Red Hat Product Errata RHSA-2025:7546 0 None None None 2025-05-14 02:00:09 UTC
Red Hat Product Errata RHSA-2025:7619 0 None None None 2025-05-14 16:17:04 UTC

Description Sandipan Roy 2022-11-10 04:53:41 UTC
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.

https://nginx.org/en/security_advisories.html

Comment 1 Sandipan Roy 2022-11-10 04:58:33 UTC
Created nginx tracking bugs for this issue:

Affects: epel-all [bug 2141498]
Affects: fedora-all [bug 2141500]


Created nginx:1.20/nginx tracking bugs for this issue:

Affects: fedora-all [bug 2141501]


Created nginx:mainline/nginx tracking bugs for this issue:

Affects: epel-all [bug 2141499]
Affects: fedora-all [bug 2141502]

Comment 16 errata-xmlrpc 2025-05-13 11:52:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:7402 https://access.redhat.com/errata/RHSA-2025:7402

Comment 17 errata-xmlrpc 2025-05-14 02:00:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:7546 https://access.redhat.com/errata/RHSA-2025:7546

Comment 18 errata-xmlrpc 2025-05-14 16:17:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:7619 https://access.redhat.com/errata/RHSA-2025:7619


Note You need to log in before you can comment on or make changes to this bug.