NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Nginx_plus | F5 | r32-p1 (including) | r32-p1 (including) |
| Nginx_plus | F5 | r32-p2 (including) | r32-p2 (including) |
| Nginx_plus | F5 | r32-p3 (including) | r32-p3 (including) |
| Nginx_plus | F5 | r32-p4 (including) | r32-p4 (including) |
| Nginx_plus | F5 | r33 (including) | r33 (including) |
| Nginx_plus | F5 | r33-p1 (including) | r33-p1 (including) |
| Nginx_plus | F5 | r33-p2 (including) | r33-p2 (including) |
| Nginx_plus | F5 | r33-p3 (including) | r33-p3 (including) |
| Nginx_plus | F5 | r34 (including) | r34 (including) |
| Nginx_plus | F5 | r34-p1 (including) | r34-p1 (including) |
| Nginx_plus | F5 | r34-p2 (including) | r34-p2 (including) |
| Nginx_plus | F5 | r35 (including) | r35 (including) |
| Nginx_plus | F5 | r35-p1 (including) | r35-p1 (including) |
| Nginx_plus | F5 | r36 (including) | r36 (including) |
| Nginx_plus | F5 | r36-p1 (including) | r36-p1 (including) |
| Nginx_plus | F5 | r36-p2 (including) | r36-p2 (including) |
| Red Hat Enterprise Linux 10 | RedHat | nginx-2:1.26.3-2.el10_1.1 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | nginx-2:1.26.3-1.el10_0.8 | * |
| Red Hat Enterprise Linux 8 | RedHat | nginx:1.24-8100020260401080144.489197e6 | * |
| Red Hat Enterprise Linux 9 | RedHat | nginx:1.24-9070020260331134728.9 | * |
| Red Hat Enterprise Linux 9 | RedHat | nginx-2:1.20.1-24.el9_7.2 | * |
| Red Hat Enterprise Linux 9 | RedHat | nginx:1.26-9070020260407080353.9 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | nginx-1:1.20.1-10.el9_0.3 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | nginx-1:1.20.1-14.el9_2.5 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | nginx-1:1.20.1-16.el9_4.5 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | nginx:1.24-9040020260504195322.9 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | nginx-2:1.20.1-22.el9_6.5 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | nginx:1.24-9060020260504194843.9 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | nginx:1.26-9060020260504154614.9 | * |
| Red Hat Hardened Images | RedHat | nginx-main-1.30.0-1.hum1 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1776868774 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1776868842 | * |
| Nginx | Ubuntu | esm-infra-legacy/trusty | * |
| Nginx | Ubuntu | esm-infra-legacy/xenial | * |
| Nginx | Ubuntu | esm-infra/bionic | * |
| Nginx | Ubuntu | esm-infra/focal | * |
| Nginx | Ubuntu | esm-infra/xenial | * |
| Nginx | Ubuntu | jammy | * |
| Nginx | Ubuntu | noble | * |
| Nginx | Ubuntu | questing | * |
| Nginx | Ubuntu | upstream | * |