RHSA-2019:2799: Important: nginx:1.14 security update
Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 (Post Office Protocol 3) and IMAP protocols, with a focus on high concurrency, performance and low memory usage. Security Fix(es): HTTP/2: large amount of data request leads to denial of service (CVE-2019-9511) HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513) HTTP/2: 0-length headers leads to denial of service (CVE-2019-9516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-all-modulesto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-filesystemto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.1-9.module+el8.0.0+4108+af250afe.aa - Upgrade
Upgrade
nginxto a version that resolves this vulnerability.Fixed in 1.14Patch CVE-2019-9511 - Upgrade
Upgrade
nginxto a version that resolves this vulnerability.Fixed in 1.14Patch CVE-2019-9516 - Upgrade
Upgrade
nginxto a version that resolves this vulnerability.Fixed in 1.14Patch CVE-2019-9513
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2799?
The severity of RHSA-2019:2799 is classified as important due to the potential for denial of service.
How do I fix RHSA-2019:2799?
To fix RHSA-2019:2799, update the nginx package to version 1.14.1-9.module+el8.0.0+4108+af250afe.
What are the affected packages in RHSA-2019:2799?
Affected packages in RHSA-2019:2799 include nginx, nginx-all-modules, nginx-filesystem, and several other nginx-related packages.
Is there a specific CVE associated with RHSA-2019:2799?
Yes, RHSA-2019:2799 addresses CVE-2019-2031 related to a denial of service vulnerability in HTTP/2.
What are the potential impacts of not addressing RHSA-2019:2799?
Not addressing RHSA-2019:2799 could lead to denial of service, affecting the availability of web services managed by nginx.