USN-7014-3: nginx vulnerability
USN-7014-1 fixed a vulnerability in nginx. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: It was discovered that the nginx ngxhttpmp4 module incorrectly handled certain malformed mp4 files. In environments where the mp4 directive is in use, a remote attacker could possibly use this issue to cause nginx to crash, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7014-3?
USN-7014-3 addresses a critical vulnerability that can lead to potential denial of service in nginx.
How do I fix USN-7014-3?
To fix USN-7014-3, update nginx to version 1.4.6-1ubuntu3.9+esm5 on Ubuntu 14.04 LTS.
Which versions of nginx are affected by USN-7014-3?
Versions of nginx below 1.4.6-1ubuntu3.9+esm5 on Ubuntu 14.04 are affected by USN-7014-3.
Is USN-7014-3 applicable to non-Ubuntu users?
USN-7014-3 specifically impacts Ubuntu 14.04 LTS users who have nginx installed.
What products are affected by USN-7014-3?
USN-7014-3 affects several nginx packages including nginx, nginx-common, nginx-core, nginx-extras, nginx-full, and nginx-light on Ubuntu 14.04.