CVE-2018-16845: High severity Apple Xcode vulnerability
IDE Xcode Server. Multiple issues were addressed by updating nginx to version 1.21.0.
Other sources
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the mp4 module that allows for denial of service or worker process memory disclosure.
— Red Hat
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngxhttpmp4module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngxhttpmp4module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngxhttpmp4module.
— Launchpad
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-16845?
CVE-2018-16845 is a vulnerability in nginx that allows an attacker to cause an infinite loop, crash a worker process, or disclose memory by using a specially crafted mp4 file.
What is the severity of CVE-2018-16845?
The severity of CVE-2018-16845 is high, with a CVSS score of 6.1.
Which software is affected by CVE-2018-16845?
Apple Xcode, Debian Linux, Canonical Ubuntu Linux, openSUSE Leap, F5 Nginx, and certain versions of nginx on Ubuntu and Red Hat are affected by CVE-2018-16845.
How can I fix CVE-2018-16845?
To fix CVE-2018-16845, update nginx to version 1.21.0 or later.
Where can I find more information about CVE-2018-16845?
You can find more information about CVE-2018-16845 at the following references: Apple support page, nginx announcement, and Red Hat Bugzilla.