[ALAS-2023-1870] Amazon Linux AMI 2014.03 - ALAS-2023-1870: important priority package update for nginx

Severity Important
Affected Packages 18
CVEs 1

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2023-44487:
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Package Affected Version
pkg:rpm/amazonlinux/nginx?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-stream?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-stream?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-mail?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-mail?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-xslt-filter?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-xslt-filter?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-perl?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-perl?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-image-filter?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-image-filter?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-geoip?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-mod-http-geoip?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-debuginfo?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-debuginfo?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-all-modules?arch=x86_64&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
pkg:rpm/amazonlinux/nginx-all-modules?arch=i686&distro=amazonlinux-1 < 1.18.0-1.45.amzn1
ID
ALAS-2023-1870
Severity
important
URL
https://alas.aws.amazon.com/ALAS-2023-1870.html
Published
2023-10-16T13:45:00
(11 months ago)
Modified
2023-10-18T20:09:00
(11 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/nginx?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx?arch=i686&distro=amazonlinux-1 amazonlinux nginx < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-mod-stream?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-mod-stream < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-mod-stream?arch=i686&distro=amazonlinux-1 amazonlinux nginx-mod-stream < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-mod-mail?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-mod-mail < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-mod-mail?arch=i686&distro=amazonlinux-1 amazonlinux nginx-mod-mail < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-mod-http-xslt-filter?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-mod-http-xslt-filter < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-mod-http-xslt-filter?arch=i686&distro=amazonlinux-1 amazonlinux nginx-mod-http-xslt-filter < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-mod-http-perl?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-mod-http-perl < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-mod-http-perl?arch=i686&distro=amazonlinux-1 amazonlinux nginx-mod-http-perl < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-mod-http-image-filter?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-mod-http-image-filter < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-mod-http-image-filter?arch=i686&distro=amazonlinux-1 amazonlinux nginx-mod-http-image-filter < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-mod-http-geoip?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-mod-http-geoip < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-mod-http-geoip?arch=i686&distro=amazonlinux-1 amazonlinux nginx-mod-http-geoip < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-debuginfo < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux nginx-debuginfo < 1.18.0-1.45.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nginx-all-modules?arch=x86_64&distro=amazonlinux-1 amazonlinux nginx-all-modules < 1.18.0-1.45.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nginx-all-modules?arch=i686&distro=amazonlinux-1 amazonlinux nginx-all-modules < 1.18.0-1.45.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...