[NGINX:CVE-2024-7347] Buffer overread in the ngx_http_mp4_module

Severity Low
Affected Packages 1
Unaffected Packages 2
CVEs 1

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Package Affected Version
pkg:nginx/nginx >= 1.5.13, <= 1.27.0
Package Unaffected Version
pkg:nginx/nginx >= 1.27.1
pkg:nginx/nginx >= 1.26.2
ID
NGINX:CVE-2024-7347
Severity
low
Published
2024-08-14T15:15:31
(4 weeks ago)
Modified
2024-08-14T15:15:31
(4 weeks ago)
Rights
NGINX Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:nginx/nginx nginx >= 1.5.13 <= 1.27.0
Unaffected pkg:nginx/nginx nginx >= 1.27.1
Unaffected pkg:nginx/nginx nginx >= 1.26.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...