CVE-2018-16845
published 2018-11-07CVE-2018-16845: nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process…
PriorityP434medium6.1CVSS 3.1
AVLACLPRNUIRSUCLINAH
EPSS
9.80%
95.0th percentile
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 13.0 | 13.0 |
| apple | xcode | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.14.1-1 (bookworm) | nginx 1.14.1-1 (bookworm) |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.4.6-1ubuntu3.9 | 1.4.6-1ubuntu3.9 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.3 | 1.10.3-0ubuntu0.16.04.3 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.2 | 1.14.0-0ubuntu1.2 |
| f5 | nginx | 1.0.7 – 1.0.15 | — |
| f5 | nginx | 1.1.3 – 1.15.5 | — |
| opensuse | leap | — | — |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.41 | 2.0.0+dfsg-2ubuntu1.41 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.28 | 1:2.5+dfsg-5ubuntu10.28 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.1 | 1:2.11+dfsg-1ubuntu7.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv10.0CRITICAL
vendor_ubuntu7.5HIGH
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-16845: Xcode 13
vendor_apple·2021-09-20·CVSS 6.1
CVE-2018-16845 [MEDIUM] CVE-2018-16845: Xcode 13
Apple Security Update: About the security content of Xcode 13
Product: Xcode
Version: 13
CVE: CVE-2018-16845
Component: CVE-2018-16845
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)
Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)
It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with
Red Hat
nginx: Denial of service and memory disclosure via mp4 module
vendor_redhat·2018-11-06·CVSS 6.1
CVE-2018-16845 [MEDIUM] CWE-191 nginx: Denial of service and memory disclosure via mp4 module
nginx: Denial of service and memory disclosure via mp4 module
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
An instance of missing input sanitization was found in the mp4 module for nginx. A local attacker could create a specially crafted video file t
Debian
CVE-2018-16845: nginx - nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_mod...
vendor_debian·2018·CVSS 6.1
CVE-2018-16845 [MEDIUM] CVE-2018-16845: nginx - nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_mod...
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye: resolved (fixed in 1.14.1-1)
forky: resolved (fixed in 1.14.1-1)
sid: resolved (fixed in 1.14.1-1)
trixie: resolved (fixed in 1.14.1-1)
GHSA
GHSA-vq5f-vpgw-9vcp: nginx before versions 1
ghsa_unreviewed·2022-05-13
CVE-2018-16845 [MEDIUM] CWE-400 GHSA-vq5f-vpgw-9vcp: nginx before versions 1
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
OSV
nginx vulnerabilities
osv·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)
Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)
It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with a specially
crafted mp4 file to cause nginx to crash, stop res
OSV
CVE-2018-16845: nginx before versions 1
osv·2018-11-07·CVSS 6.1
CVE-2018-16845 [MEDIUM] CVE-2018-16845: nginx before versions 1
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
OSV
qemu vulnerabilities
osv·2018-05-16·CVSS 10.0
CVE-2017-16845 qemu vulnerabilities
qemu vulnerabilities
Cyrille Chatras discovered that QEMU incorrectly handled certain PS2 values
during migration. An attacker could possibly use this issue to cause QEMU
to crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 18.04 LTS. (CVE-2017-16845)
Cyrille Chatras discovered that QEMU incorrectly handled multiboot. An
attacker could use this issue to cause QEMU to crash, resulting in a denial
of service, or possibly execute arbitrary code on the host. In the default
installation, when QEMU is used with libvirt, attackers would be isolated
by the libvirt AppArmor profile. (CVE-2018-7550)
Ross Lagerwall discovered that QEMU incorrectly handled the Cirrus VGA
device. A privileged attacker inside the guest could use this issue to
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module [epel-all]
bugzilla·2018-11-07·CVSS 6.1
CVE-2018-16845 [MEDIUM] CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module [epel-all]
CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module [fedora-all]
bugzilla·2018-11-07·CVSS 6.1
CVE-2018-16845 [MEDIUM] CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module [fedora-all]
CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module
bugzilla·2018-10-31·CVSS 6.1
CVE-2018-16845 [MEDIUM] CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module
CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the mp4 module that allows for denial of service or worker process memory disclosure.
Discussion:
Acknowledgments:
Name: the Nginx project
---
Ansible Tower is not using ngx_http_mp4_module at all, therefore is not affected.
---
Already did some research and discuss with Satoe I. from CloudForms. CFME is not using in any way nginx more than the inclusion from Ansible Tower (not changed or altered configuration or used outside from Tower), and Ansible Tower is not affected, so CloudForms is also not affected; updating the task accordingly.
---
External Reference:
http://mailman.nginx.org/pipermail/nginx-announce/2018/000221.html
Upstream Pa
Bugzilla
CVE-2017-16845 Qemu: ps2: information leakage via post_load routine
bugzilla·2017-11-16·CVSS 10.0
CVE-2017-16845 [CRITICAL] CVE-2017-16845 Qemu: ps2: information leakage via post_load routine
CVE-2017-16845 Qemu: ps2: information leakage via post_load routine
Quick Emulator(Qemu) built with the PS/2 keyboard and mouse emulation
support along with the migration feature enabled is vulnerable to an
information leakage flaw. It could occur while loading a migrated
snapshot on the destination host in PS2 post_load routine.
A privileged user could use this flaw to leak destination host memory
bytes.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2018-01/msg06643.html
Reference:
-> http://www.openwall.com/lists/oss-security/2017/11/17/1
Discussion:
Acknowledgments:
Name: Cyrille Chatras (Orange.com)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1514150]
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1514149]
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2018/000221.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/105868http://www.securitytracker.com/id/1042039https://access.redhat.com/errata/RHSA-2018:3652https://access.redhat.com/errata/RHSA-2018:3653https://access.redhat.com/errata/RHSA-2018:3680https://access.redhat.com/errata/RHSA-2018:3681https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16845https://lists.debian.org/debian-lts-announce/2018/11/msg00010.htmlhttps://support.apple.com/kb/HT212818https://usn.ubuntu.com/3812-1/https://www.debian.org/security/2018/dsa-4335http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2018/000221.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/105868http://www.securitytracker.com/id/1042039https://access.redhat.com/errata/RHSA-2018:3652https://access.redhat.com/errata/RHSA-2018:3653https://access.redhat.com/errata/RHSA-2018:3680https://access.redhat.com/errata/RHSA-2018:3681https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16845https://lists.debian.org/debian-lts-announce/2018/11/msg00010.htmlhttps://support.apple.com/kb/HT212818https://usn.ubuntu.com/3812-1/https://www.debian.org/security/2018/dsa-4335
2018-11-07
Published