Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:2799

Опубликовано: 17 сент. 2019
Источник: rocky
Оценка: Important

Описание

Important: nginx:1.14 security update

Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 (Post Office Protocol 3) and IMAP protocols, with a focus on high concurrency, performance and low memory usage.

Security Fix(es):

  • HTTP/2: large amount of data request leads to denial of service (CVE-2019-9511)

  • HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513)

  • HTTP/2: 0-length headers leads to denial of service (CVE-2019-9516)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
nginxx86_649.module+el8.4.0+542+81547229nginx-1.14.1-9.module+el8.4.0+542+81547229.x86_64.rpm
nginx-all-modulesnoarch9.module+el8.4.0+542+81547229nginx-all-modules-1.14.1-9.module+el8.4.0+542+81547229.noarch.rpm
nginx-filesystemnoarch9.module+el8.4.0+542+81547229nginx-filesystem-1.14.1-9.module+el8.4.0+542+81547229.noarch.rpm
nginx-mod-http-image-filterx86_649.module+el8.4.0+542+81547229nginx-mod-http-image-filter-1.14.1-9.module+el8.4.0+542+81547229.x86_64.rpm
nginx-mod-http-perlx86_649.module+el8.4.0+542+81547229nginx-mod-http-perl-1.14.1-9.module+el8.4.0+542+81547229.x86_64.rpm
nginx-mod-http-xslt-filterx86_649.module+el8.4.0+542+81547229nginx-mod-http-xslt-filter-1.14.1-9.module+el8.4.0+542+81547229.x86_64.rpm
nginx-mod-mailx86_649.module+el8.4.0+542+81547229nginx-mod-mail-1.14.1-9.module+el8.4.0+542+81547229.x86_64.rpm
nginx-mod-streamx86_649.module+el8.4.0+542+81547229nginx-mod-stream-1.14.1-9.module+el8.4.0+542+81547229.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
больше 5 лет назад

Security update for nginx

suse-cvrf
больше 5 лет назад

Security update for nginx

oracle-oval
почти 6 лет назад

ELSA-2019-2799: nginx:1.14 security update (IMPORTANT)

suse-cvrf
почти 6 лет назад

Security update for nginx

suse-cvrf
почти 6 лет назад

Security update for nginx