Out-of-bounds read in NGINX Plus and NGINX Open Source - CVE-2024-7347

 

Out-of-bounds read in NGINX Plus and NGINX Open Source - CVE-2024-7347

Published: August 14, 2024 / Updated: August 20, 2024


Vulnerability identifier: #VU96020
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-7347
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the ngx_http_mp4_module when reading mp4 files. A remote attacker can pass a specially crafted file to the web server, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Successful exploitation of the vulnerability requires that the server is built with the ngx_http_mp4_module and the "mp4" directive is used in the configuration file.


Affected software

NGINX Plus
NGINX Open Source
SUSE Linux Enterprise Server 15 SP4
Oracle Linux
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
Server Applications Module
openSUSE Leap
openEuler
Fedora
IBM Integrated Analytics System
EasyApache
Sensor Proxy
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
Session Smart Router
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nginx-extras (Ubuntu package)
nginx (Ubuntu package)
nginx-common (Ubuntu package)
nginx-core (Ubuntu package)
nginx-full (Ubuntu package)
nginx-light (Ubuntu package)
nginx-mod-vts
nginx-mod-fancyindex
nginx-mod-modsecurity
nginx-mod-naxsi
nginx (Red Hat package)
nginx
nginx-debugsource
nginx-mod-devel
nginx-mod-http-image-filter
nginx-debuginfo
nginx-mod-mail
nginx-mod-http-perl
nginx-mod-http-xslt-filter
nginx-filesystem
nginx-all-modules
nginx-mod-stream
nginx-help
nginx-source
www-servers/nginx
APEX Cloud Platform for Microsoft Azure
Robotic Process Automation for Cloud Pak
IBM API Connect

How to mitigate CVE-2024-7347

Install updates from vendor's website.

NGINX Plus - addressed in versions R31 P3, R32 P1
NGINX Open Source - addressed in versions 1.26.2, 1.27.1
IBM Integrated Analytics System - update to 1.0.31.0
EasyApache - update to 4 2024-8-21
nginx-extras (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-common (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-core (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-full (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-light (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-mod-vts - addressed in versions 0.2.2-9.fc39, 0.2.2-9.fc40
nginx-mod-fancyindex - addressed in versions 0.5.2-5.fc39, 0.5.2-7.fc40
nginx-mod-modsecurity - addressed in versions 1.0.3-13.fc39, 1.0.3-13.fc40
Sensor Proxy - update to 1.4.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
nginx-mod-naxsi - addressed in versions 1.6-6.fc39, 1.6-6.fc40
nginx (Red Hat package) - addressed in versions 1.20.1-16.el9_4.3, 1.20.1-22.el9_6.2
nginx - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-debugsource - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-devel - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-http-image-filter - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-debuginfo - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-mail - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-http-perl - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-http-xslt-filter - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-filesystem - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-all-modules - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-stream - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-help - addressed in versions 1.21.5-7, 1.24.0-2
nginx-source - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
nginx-debugsource - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
nginx-debuginfo - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
nginx - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
www-servers/nginx - update to 1.26.2-r2
nginx - addressed in versions 1.26.2-1.fc39, 1.26.2-1.fc40
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3, 5.1.0
Session Smart Router - addressed in versions 6.2.10, 6.3.7
IBM API Connect - update to 10.0.9.0
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.19

External References

Related Security Bulletins