REDHAT-BUG-2449598: High severity Nginx NGINX Open Source vulnerability
Out-of-Bounds Read/Write vulnerability in the ngxhttpmp4module of NGINX Open Source and NGINX Plus. The flaw is caused by improper handling of specially crafted MP4 files during processing. When such a file is parsed, it can trigger a buffer over-read or overwrite in worker memory, leading to process termination or undefined behavior. This vulnerability can be exploited by a local authenticated attacker capable of supplying a malicious MP4 file, potentially causing denial-of-service or achieving code execution under certain conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2449598?
REDHAT-BUG-2449598 is classified as a medium severity vulnerability.
How do I fix REDHAT-BUG-2449598?
To fix REDHAT-BUG-2449598, update to the patched versions of NGINX Open Source or NGINX Plus recommended by the vendor.
What types of systems are affected by REDHAT-BUG-2449598?
REDHAT-BUG-2449598 affects NGINX Open Source and NGINX Plus installations that process specially crafted MP4 files.
What consequences can arise from REDHAT-BUG-2449598?
Exploitation of REDHAT-BUG-2449598 can lead to out-of-bounds read or write, which may compromise worker memory integrity.
How does REDHAT-BUG-2449598 affect NGINX's functionality?
REDHAT-BUG-2449598 can disrupt NGINX's ability to correctly handle certain MP4 files, potentially resulting in service interruptions.