USN-7014-2: nginx vulnerability
USN-7014-1 fixed a vulnerability in nginx. This update provides the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that the nginx ngxhttpmp4 module incorrectly handled certain malformed mp4 files. In environments where the mp4 directive is in use, a remote attacker could possibly use this issue to cause nginx to crash, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7014-2?
The USN-7014-2 vulnerability is classified as high severity due to its potential to cause denial of service in systems handling malformed mp4 files.
How do I fix USN-7014-2?
To fix USN-7014-2, update nginx to version 1.14.0-0ubuntu1.11+esm1 on Ubuntu 18.04 or 1.10.3-0ubuntu0.16.04.5+esm6 on Ubuntu 16.04.
Which versions of Ubuntu are affected by USN-7014-2?
USN-7014-2 affects Ubuntu 16.04 LTS and Ubuntu 18.04 LTS installations running vulnerable versions of nginx.
What component of nginx is affected by USN-7014-2?
The vulnerability in USN-7014-2 specifically affects the ngx_http_mp4 module in nginx.
Was USN-7014-2 a follow-up to an earlier advisory?
Yes, USN-7014-2 is a follow-up to the earlier USN-7014-1 advisory, providing updates for affected Ubuntu versions.