First published: Wed Oct 19 2022(Updated: )
NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file. The issue affects only NGINX Plus when the hls directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_hls_module.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 NGINX Ingress Controller | >=1.9.0<=1.12.4 | |
F5 NGINX Ingress Controller | >=2.0.0<=2.4.0 | |
F5 NGINX Plus | >=r22<=r27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41743 is a vulnerability in NGINX Plus before versions R27 P1 and R26 P1 that allows a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file.
The affected software includes NGINX Plus versions R27 and R26.
CVE-2022-41743 has a severity level of high.
To fix CVE-2022-41743, upgrade to NGINX Plus versions R27 P1 or R26 P1, which include the necessary security patches.
You can find more information about CVE-2022-41743 on the F5 support website at the following link: [https://support.f5.com/csp/article/K01112063]