[USN-4099-1] nginx vulnerabilities

Severity Medium
Affected Packages 59
CVEs 3

nginx could be made to crash if it received specially crafted network traffic.

Jonathan Looney discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to consume
resources, leading to a denial of service.

Package Affected Version
pkg:deb/ubuntu/nginx?distro=xenial < 1.10.3-0ubuntu0.16.04.4
pkg:deb/ubuntu/nginx?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/nginx?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/nginx-light?distro=xenial < 1.10.3-0ubuntu0.16.04.4
pkg:deb/ubuntu/nginx-light?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/nginx-light?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/nginx-full?distro=xenial < 1.10.3-0ubuntu0.16.04.4
pkg:deb/ubuntu/nginx-full?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/nginx-full?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/nginx-extras?distro=xenial < 1.10.3-0ubuntu0.16.04.4
pkg:deb/ubuntu/nginx-extras?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/nginx-extras?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/nginx-doc?distro=xenial < 1.10.3-0ubuntu0.16.04.4
pkg:deb/ubuntu/nginx-doc?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/nginx-doc?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/nginx-core?distro=xenial < 1.10.3-0ubuntu0.16.04.4
pkg:deb/ubuntu/nginx-core?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/nginx-core?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/nginx-common?distro=xenial < 1.10.3-0ubuntu0.16.04.4
pkg:deb/ubuntu/nginx-common?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/nginx-common?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-stream?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-stream?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-rtmp?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-rtmp?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-nchan?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-nchan?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-mail?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-mail?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-xslt-filter?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-xslt-filter?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-upstream-fair?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-upstream-fair?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-uploadprogress?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-uploadprogress?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-subs-filter?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-subs-filter?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-perl?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-perl?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-ndk?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-ndk?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-lua?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-lua?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-image-filter?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-image-filter?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-headers-more-filter?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-headers-more-filter?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-geoip?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-geoip?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-fancyindex?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-fancyindex?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-echo?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-echo?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-dav-ext?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-dav-ext?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-cache-purge?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-cache-purge?distro=bionic < 1.14.0-0ubuntu1.4
pkg:deb/ubuntu/libnginx-mod-http-auth-pam?distro=disco < 1.15.9-0ubuntu1.1
pkg:deb/ubuntu/libnginx-mod-http-auth-pam?distro=bionic < 1.14.0-0ubuntu1.4
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/nginx?distro=xenial ubuntu nginx < 1.10.3-0ubuntu0.16.04.4 xenial
Affected pkg:deb/ubuntu/nginx?distro=disco ubuntu nginx < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/nginx?distro=bionic ubuntu nginx < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/nginx-light?distro=xenial ubuntu nginx-light < 1.10.3-0ubuntu0.16.04.4 xenial
Affected pkg:deb/ubuntu/nginx-light?distro=disco ubuntu nginx-light < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/nginx-light?distro=bionic ubuntu nginx-light < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/nginx-full?distro=xenial ubuntu nginx-full < 1.10.3-0ubuntu0.16.04.4 xenial
Affected pkg:deb/ubuntu/nginx-full?distro=disco ubuntu nginx-full < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/nginx-full?distro=bionic ubuntu nginx-full < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/nginx-extras?distro=xenial ubuntu nginx-extras < 1.10.3-0ubuntu0.16.04.4 xenial
Affected pkg:deb/ubuntu/nginx-extras?distro=disco ubuntu nginx-extras < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/nginx-extras?distro=bionic ubuntu nginx-extras < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/nginx-doc?distro=xenial ubuntu nginx-doc < 1.10.3-0ubuntu0.16.04.4 xenial
Affected pkg:deb/ubuntu/nginx-doc?distro=disco ubuntu nginx-doc < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/nginx-doc?distro=bionic ubuntu nginx-doc < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/nginx-core?distro=xenial ubuntu nginx-core < 1.10.3-0ubuntu0.16.04.4 xenial
Affected pkg:deb/ubuntu/nginx-core?distro=disco ubuntu nginx-core < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/nginx-core?distro=bionic ubuntu nginx-core < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/nginx-common?distro=xenial ubuntu nginx-common < 1.10.3-0ubuntu0.16.04.4 xenial
Affected pkg:deb/ubuntu/nginx-common?distro=disco ubuntu nginx-common < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/nginx-common?distro=bionic ubuntu nginx-common < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-stream?distro=disco ubuntu libnginx-mod-stream < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-stream?distro=bionic ubuntu libnginx-mod-stream < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-rtmp?distro=disco ubuntu libnginx-mod-rtmp < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-rtmp?distro=bionic ubuntu libnginx-mod-rtmp < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-nchan?distro=disco ubuntu libnginx-mod-nchan < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-nchan?distro=bionic ubuntu libnginx-mod-nchan < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-mail?distro=disco ubuntu libnginx-mod-mail < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-mail?distro=bionic ubuntu libnginx-mod-mail < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-xslt-filter?distro=disco ubuntu libnginx-mod-http-xslt-filter < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-xslt-filter?distro=bionic ubuntu libnginx-mod-http-xslt-filter < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-upstream-fair?distro=disco ubuntu libnginx-mod-http-upstream-fair < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-upstream-fair?distro=bionic ubuntu libnginx-mod-http-upstream-fair < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-uploadprogress?distro=disco ubuntu libnginx-mod-http-uploadprogress < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-uploadprogress?distro=bionic ubuntu libnginx-mod-http-uploadprogress < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-subs-filter?distro=disco ubuntu libnginx-mod-http-subs-filter < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-subs-filter?distro=bionic ubuntu libnginx-mod-http-subs-filter < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-perl?distro=disco ubuntu libnginx-mod-http-perl < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-perl?distro=bionic ubuntu libnginx-mod-http-perl < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-ndk?distro=disco ubuntu libnginx-mod-http-ndk < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-ndk?distro=bionic ubuntu libnginx-mod-http-ndk < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-lua?distro=disco ubuntu libnginx-mod-http-lua < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-lua?distro=bionic ubuntu libnginx-mod-http-lua < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-image-filter?distro=disco ubuntu libnginx-mod-http-image-filter < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-image-filter?distro=bionic ubuntu libnginx-mod-http-image-filter < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-headers-more-filter?distro=disco ubuntu libnginx-mod-http-headers-more-filter < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-headers-more-filter?distro=bionic ubuntu libnginx-mod-http-headers-more-filter < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-geoip?distro=disco ubuntu libnginx-mod-http-geoip < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-geoip?distro=bionic ubuntu libnginx-mod-http-geoip < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-fancyindex?distro=disco ubuntu libnginx-mod-http-fancyindex < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-fancyindex?distro=bionic ubuntu libnginx-mod-http-fancyindex < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-echo?distro=disco ubuntu libnginx-mod-http-echo < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-echo?distro=bionic ubuntu libnginx-mod-http-echo < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-dav-ext?distro=disco ubuntu libnginx-mod-http-dav-ext < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-dav-ext?distro=bionic ubuntu libnginx-mod-http-dav-ext < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-cache-purge?distro=disco ubuntu libnginx-mod-http-cache-purge < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-cache-purge?distro=bionic ubuntu libnginx-mod-http-cache-purge < 1.14.0-0ubuntu1.4 bionic
Affected pkg:deb/ubuntu/libnginx-mod-http-auth-pam?distro=disco ubuntu libnginx-mod-http-auth-pam < 1.15.9-0ubuntu1.1 disco
Affected pkg:deb/ubuntu/libnginx-mod-http-auth-pam?distro=bionic ubuntu libnginx-mod-http-auth-pam < 1.14.0-0ubuntu1.4 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...