NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r35:*:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "r32-p1"
},
{
"last_affected": "r32-p1"
},
{
"introduced": "r32-p2"
},
{
"last_affected": "r32-p2"
},
{
"introduced": "r32-p3"
},
{
"last_affected": "r32-p3"
},
{
"introduced": "r32-p4"
},
{
"last_affected": "r32-p4"
},
{
"introduced": "r33"
},
{
"last_affected": "r33"
},
{
"introduced": "r33-p1"
},
{
"last_affected": "r33-p1"
},
{
"introduced": "r33-p2"
},
{
"last_affected": "r33-p2"
},
{
"introduced": "r33-p3"
},
{
"last_affected": "r33-p3"
},
{
"introduced": "r34"
},
{
"last_affected": "r34"
},
{
"introduced": "r34-p1"
},
{
"last_affected": "r34-p1"
},
{
"introduced": "r34-p2"
},
{
"last_affected": "r34-p2"
},
{
"introduced": "r35"
},
{
"last_affected": "r35"
},
{
"introduced": "r35-p1"
},
{
"last_affected": "r35-p1"
},
{
"introduced": "r36"
},
{
"last_affected": "r36"
},
{
"introduced": "r36-p1"
},
{
"last_affected": "r36-p1"
},
{
"introduced": "r36-p2"
},
{
"last_affected": "r36-p2"
}
],
"source": "CPE_STRING",
"vendor_product": "f5:nginx_plus"
}
]
}