Description Preview
The vulnerability in nginx versions 1.15.6 and 1.14.1 exists in the ngx_http_mp4_module, which can be exploited by an attacker to trigger an infinite loop, crash a worker process, or disclose memory contents. This issue only affects nginx if it is built with the ngx_http_mp4_module and the .mp4 directive is used in the configuration file. An attacker needs to be able to trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module to exploit this vulnerability.
Overview
- CVE ID: CVE-2018-16845
- CVSS Score: 8.2 (High)
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: High
- CWE ID: CWE-400
- Affected Versions: nginx 1.15.6, 1.14.1
- Publication Date: 2018-11-06
Remediation
To remediate this vulnerability, users are advised to take the following actions:
- Upgrade to a non-affected version of nginx.
- If upgrading is not immediately possible, consider disabling the ngx_http_mp4_module or avoiding the use of the .mp4 directive in the configuration file.
- Regularly monitor for security advisories and apply patches promptly.
References
- Debian Security Advisory DSA-4335: Link
- Red Hat Security Advisory RHSA-2018:3680: Link
- Red Hat Security Advisory RHSA-2018:3681: Link
- SecurityFocus BID 105868: Link
- Red Hat Bugzilla CVE-2018-16845: Link
- SecurityTracker ID 1042039: Link
- Debian LTS Announce 20181108 DLA 1572-1: Link
- Red Hat Security Advisory RHSA-2018:3653: Link
- Red Hat Security Advisory RHSA-2018:3652: Link
- Ubuntu Security Notice USN-3812-1: Link
- Nginx Mailing List Announcement: Link
- openSUSE-SU-2019:2120: Link
- Apple Support KB HT212818: Link
- Full Disclosure Mailing List Announcement: Link
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- Educational ServicesEducational Services
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Transportation & WarehousingTransportation & Warehousing
- Public AdministrationPublic Administration
- Retail TradeRetail Trade
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Other Services (except Public Administration)Other Services (except Public Administration)
- UtilitiesUtilities
- Wholesale TradeWholesale Trade
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- InformationInformation
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing