Debian Security Advisory
DLA-1572-1 nginx -- LTS security update
- Date Reported:
- 08 Nov 2018
- Affected Packages:
- nginx
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-16845.
- More information:
-
It was discovered that there was a denial of service (DoS) vulnerability in the nginx web/proxy server.
As there was no validation for the size of a 64-bit atom in an MP4 file, this could have led to a CPU hog when the size was 0, or various other problems due to integer underflow when the calculating atom data size, including segmentation faults or even worker-process memory disclosure.
For Debian 8
Jessie
, this issue has been fixed in nginx version 1.6.2-5+deb8u6.We recommend that you upgrade your nginx packages.