USN-7014-1: nginx vulnerability
It was discovered that the nginx ngxhttpmp4 module incorrectly handled certain malformed mp4 files. In environments where the mp4 directive is in use, a remote attacker could possibly use this issue to cause nginx to crash, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7014-1?
The severity of USN-7014-1 is categorized as a denial of service vulnerability due to improper handling of malformed mp4 files in the nginx ngx_http_mp4 module.
How do I fix USN-7014-1?
To fix USN-7014-1, you should upgrade to nginx versions 1.24.0-2ubuntu7.1, 1.18.0-6ubuntu14.5, or 1.18.0-0ubuntu1.6 depending on your Ubuntu version.
What components are affected by USN-7014-1?
USN-7014-1 affects several nginx packages including nginx, nginx-common, nginx-core, nginx-extras, nginx-full, and nginx-light on specific versions of Ubuntu.
Can USN-7014-1 lead to server downtime?
Yes, USN-7014-1 can lead to server downtime as it allows remote attackers to crash the nginx server by exploiting malformed mp4 files.
Is there a workaround for USN-7014-1?
While upgrading is the best solution for USN-7014-1, a temporary workaround involves disabling the mp4 directive if it's not essential for your environment.