Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:0282-1

Опубликовано: 29 янв. 2025
Источник: suse-cvrf

Описание

Security update for nginx

This update for nginx fixes the following issues:

  • CVE-2023-44487: Mitigate HTTP/2 Rapid Reset Attack (bsc#1216171)
  • CVE-2024-7347: Fixed worker crashes on special crafted mp4 files containing invalid chunk information (bsc#1229155)

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise Server 15 SP4-LTSS
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise Server 15 SP5-LTSS
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Manager Proxy 4.3
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1
SUSE Manager Server 4.3
nginx-1.21.5-150400.3.6.1
nginx-source-1.21.5-150400.3.6.1

Описание

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:nginx-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:nginx-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:nginx-source-1.21.5-150400.3.6.1

Ссылки

Описание

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:nginx-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:nginx-source-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:nginx-1.21.5-150400.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:nginx-source-1.21.5-150400.3.6.1

Ссылки
Уязвимость SUSE-SU-2025:0282-1