F5-K000140529: Medium severity nginx vulnerability
NGINX Open Source and NGINX Plus have a vulnerability in the ngxhttpmp4module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngxhttpmp4module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngxhttpmp4module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000140529?
The severity of F5-K000140529 is considered critical due to the potential for memory over-read and termination of NGINX services.
How do I fix F5-K000140529?
To fix F5-K000140529, update NGINX Open Source to version 1.27.11.26.2 or NGINX Plus to version 27 or later.
What systems are affected by F5-K000140529?
F5-K000140529 affects NGINX Open Source versions between 1.5.13 and 1.26.1 and NGINX Plus version 27 if built with ngx_http_mp4_module.
What methods can be used to mitigate the risks of F5-K000140529?
Mitigation for F5-K000140529 includes disabling the ngx_http_mp4_module if it is not required for your applications.
Is this vulnerability specific to any version of NGINX?
Yes, F5-K000140529 specifically impacts certain versions of NGINX Open Source and NGINX Plus that utilize the ngx_http_mp4_module.