Debian Security Advisory

DLA-1572-1 nginx -- LTS security update

Date Reported:
08 Nov 2018
Affected Packages:
nginx
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-16845.
More information:

It was discovered that there was a denial of service (DoS) vulnerability in the nginx web/proxy server.

As there was no validation for the size of a 64-bit atom in an MP4 file, this could have led to a CPU hog when the size was 0, or various other problems due to integer underflow when the calculating atom data size, including segmentation faults or even worker-process memory disclosure.

For Debian 8 Jessie, this issue has been fixed in nginx version 1.6.2-5+deb8u6.

We recommend that you upgrade your nginx packages.