Out-of-bounds read in NGINX Open Source - CVE-2022-41741

 

Out-of-bounds read in NGINX Open Source - CVE-2022-41741

Published: October 19, 2022


Vulnerability identifier: #VU68494
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41741
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform a denial of service attack.

The vulnerability exists due to a boundary condition within the ngx_http_mp4_module module when handling MP4 files. A remote attacker can pass a specially crafted file to the server, trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service attack.


Affected software

NGINX Open Source
Amazon Linux AMI
Debian Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
openEuler
Junos OS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nginx-core (Ubuntu package)
nginx-full (Ubuntu package)
nginx-extras (Ubuntu package)
nginx-common (Ubuntu package)
nginx (Ubuntu package)
nginx-light (Ubuntu package)
nginx
nginx-debugsource
nginx-debuginfo
nginx-source
nginx (Debian package)
vim-plugin-nginx
nginx (Red Hat package)
nginx-mod-mail
nginx-filesystem
nginx-help
nginx-all-modules
nginx-mod-http-xslt-filter
nginx-mod-http-perl
nginx-mod-stream
nginx-mod-http-image-filter
IBM Process Mining
Session Smart Router
IBM Robotic Process Automation
VMware Tanzu Operations Manager
PowerFlex rack
Watson Studio on Cloud Pak for Data
HPE Moonshot 1500 Chassis Manager
RecoverPoint for VMs

How to mitigate CVE-2022-41741

Install updates from vendor's website.

NGINX Open Source - addressed in versions 1.22.1, 1.23.2
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
nginx-core (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.11, 1.18.0-0ubuntu1.4, 1.18.0-6ubuntu14.3, 1.22.0-1ubuntu1.1
nginx-full (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.11, 1.18.0-0ubuntu1.4, 1.18.0-6ubuntu14.3, 1.22.0-1ubuntu1.1
nginx-extras (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.11, 1.18.0-0ubuntu1.4, 1.18.0-6ubuntu14.3, 1.22.0-1ubuntu1.1
nginx-common (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.11, 1.18.0-0ubuntu1.4, 1.18.0-6ubuntu14.3, 1.22.0-1ubuntu1.1
nginx (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.11, 1.18.0-0ubuntu1.4, 1.18.0-6ubuntu14.3, 1.22.0-1ubuntu1.1
nginx-light (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.11, 1.18.0-0ubuntu1.4, 1.18.0-6ubuntu14.3, 1.22.0-1ubuntu1.1
nginx - addressed in versions mainline-820220816123924.9edba152, mainline-3520221019155610.f27b74a8, mainline-3620221019155610.5e5ad4a0, mainline-3720221019155610.9e842022, 1.20.1-10.el7, 1.20-3520221110171337.f27b74a8, 1.20-3620221110171337.5e5ad4a0, 1.20-3720221110171337.9e842022, 1.22.1-1.fc35, 1.22.1-1.fc36, 1.22.1-1.fc37
IBM Process Mining - update to 1.15.0 IF004
nginx-debugsource - addressed in versions 1.16.1-150100.6.19.1, 1.16.1-150200.3.12.1, 1.19.8-150300.3.12.1, 1.21.5-150400.3.3.1
nginx - addressed in versions 1.16.1-150100.6.19.1, 1.16.1-150200.3.12.1, 1.19.8-150300.3.12.1, 1.21.5-150400.3.3.1
nginx-debuginfo - addressed in versions 1.16.1-150100.6.19.1, 1.16.1-150200.3.12.1, 1.19.8-150300.3.12.1, 1.21.5-150400.3.3.1
nginx-source - addressed in versions 1.16.1-150100.6.19.1, 1.16.1-150200.3.12.1, 1.19.8-150300.3.12.1, 1.21.5-150400.3.3.1
nginx - addressed in versions 1.18.0-1.44, 1.22.1-1
nginx (Debian package) - update to 1.18.0-6.1+deb11u3
vim-plugin-nginx - update to 1.19.8-150300.3.12.1
nginx (Red Hat package) - addressed in versions 1.20.1-16.el9_4.3, 1.20.1-22.el9_6.2
nginx-mod-mail - update to 1.21.5-2
nginx-filesystem - update to 1.21.5-2
nginx-help - update to 1.21.5-2
nginx-all-modules - update to 1.21.5-2
nginx-mod-http-xslt-filter - update to 1.21.5-2
nginx-mod-http-perl - update to 1.21.5-2
nginx-mod-stream - update to 1.21.5-2
nginx-mod-http-image-filter - update to 1.21.5-2
nginx-debugsource - update to 1.21.5-2
nginx-debuginfo - update to 1.21.5-2
nginx - update to 1.21.5-2
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
PowerFlex rack - update to 3.6.6.0
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Session Smart Router - addressed in versions 5.6.14, 6.1.8, 6.2.5-r2, 6.2.10, 6.3.0, 6.3.7
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Robotic Process Automation - update to 21.0.7

External References

Related Security Bulletins