First published: Wed Oct 31 2018(Updated: )
IDE Xcode Server. Multiple issues were addressed by updating nginx to version 1.21.0.
Credit: CVE-2016-0742 CVE-2016-0746 CVE-2016-0747 CVE-2017-7529 CVE-2018-16843 CVE-2018-16844 CVE-2018-16845 CVE-2019-20372 secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Nginx | >=1.9.5<1.14.1 | |
F5 Nginx | >=1.15.0<1.15.6 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Apple Xcode | <13.0 | |
Apple Xcode | <13 | 13 |
redhat/nginx | <1.15.6 | 1.15.6 |
redhat/nginx | <1.14.1 | 1.14.1 |
debian/nginx | 1.18.0-6.1+deb11u3 1.22.1-9 1.26.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-16844 is a vulnerability in nginx before versions 1.15.6 and 1.14.1 that allows for excessive CPU usage due to a flaw in the implementation of HTTP/2.
Users of the affected versions of nginx (1.15.6 and 1.14.1) and Xcode are affected by CVE-2018-16844.
To fix CVE-2018-16844, update nginx to version 1.21.0 or later.
You can find more information about CVE-2018-16844 in the references provided.
CVE-2018-16844 has a severity rating of 7.5 (high).