USN-3812-1: nginx vulnerabilities
It was discovered that nginx incorrectly handled the HTTP/2 implementation. A remote attacker could possibly use this issue to cause excessive memory consumption, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843) Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2 implementation. A remote attacker could possibly use this issue to cause excessive CPU usage, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16844) It was discovered that nginx incorrectly handled the ngxhttpmp4module module. A remote attacker could possibly use this issue with a specially crafted mp4 file to cause nginx to crash, stop responding, or access arbitrary memory. (CVE-2018-16845)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2018-16843.
What is the impact of CVE-2018-16843?
CVE-2018-16843 can lead to excessive memory consumption, resulting in a denial of service.
Which versions of Ubuntu are affected by this vulnerability?
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10 are affected by CVE-2018-16843.
How can I fix the CVE-2018-16843 vulnerability?
To fix the CVE-2018-16843 vulnerability, you need to update the affected software to version 1.15.5-0ubuntu2.1 for Ubuntu 18.10, version 1.14.0-0ubuntu1.2 for Ubuntu 18.04 LTS, and version 1.10.3-0ubuntu0.16.04.3 for Ubuntu 16.04 LTS.
Where can I find more information about CVE-2018-16843?
You can find more information about CVE-2018-16843 in the Ubuntu Security Advisory USN-3812-1.