Out-of-bounds read in NGINX Plus and NGINX Open Source - CVE-2024-7347
Published: August 14, 2024 / Updated: August 20, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the ngx_http_mp4_module when reading mp4 files. A remote attacker can pass a specially crafted file to the web server, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that the server is built with the ngx_http_mp4_module and the "mp4" directive is used in the configuration file.
Affected software
NGINX Open Source
SUSE Linux Enterprise Server 15 SP4
Oracle Linux
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
Server Applications Module
openSUSE Leap
openEuler
Fedora
IBM Integrated Analytics System
EasyApache
Sensor Proxy
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
Session Smart Router
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nginx-extras (Ubuntu package)
nginx (Ubuntu package)
nginx-common (Ubuntu package)
nginx-core (Ubuntu package)
nginx-full (Ubuntu package)
nginx-light (Ubuntu package)
nginx-mod-vts
nginx-mod-fancyindex
nginx-mod-modsecurity
nginx-mod-naxsi
nginx (Red Hat package)
nginx
nginx-debugsource
nginx-mod-devel
nginx-mod-http-image-filter
nginx-debuginfo
nginx-mod-mail
nginx-mod-http-perl
nginx-mod-http-xslt-filter
nginx-filesystem
nginx-all-modules
nginx-mod-stream
nginx-help
nginx-source
www-servers/nginx
APEX Cloud Platform for Microsoft Azure
Robotic Process Automation for Cloud Pak
IBM API Connect
How to mitigate CVE-2024-7347
NGINX Open Source - addressed in versions 1.26.2, 1.27.1
IBM Integrated Analytics System - update to 1.0.31.0
EasyApache - update to 4 2024-8-21
nginx-extras (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-common (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-core (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-full (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-light (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.24.0-2ubuntu7.1
nginx-mod-vts - addressed in versions 0.2.2-9.fc39, 0.2.2-9.fc40
nginx-mod-fancyindex - addressed in versions 0.5.2-5.fc39, 0.5.2-7.fc40
nginx-mod-modsecurity - addressed in versions 1.0.3-13.fc39, 1.0.3-13.fc40
Sensor Proxy - update to 1.4.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
nginx-mod-naxsi - addressed in versions 1.6-6.fc39, 1.6-6.fc40
nginx (Red Hat package) - addressed in versions 1.20.1-16.el9_4.3, 1.20.1-22.el9_6.2
nginx - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-debugsource - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-devel - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-http-image-filter - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-debuginfo - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-mail - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-http-perl - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-http-xslt-filter - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-filesystem - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-all-modules - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-mod-stream - addressed in versions 1.21.5-5, 1.21.5-7, 1.24.0-2
nginx-help - addressed in versions 1.21.5-7, 1.24.0-2
nginx-source - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
nginx-debugsource - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
nginx-debuginfo - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
nginx - addressed in versions 1.21.5-150400.3.6.1, 1.21.5-150600.10.3.1
www-servers/nginx - update to 1.26.2-r2
nginx - addressed in versions 1.26.2-1.fc39, 1.26.2-1.fc40
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3, 5.1.0
Session Smart Router - addressed in versions 6.2.10, 6.3.7
IBM API Connect - update to 10.0.9.0
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.19
External References
Related Security Bulletins
- Denial of service in nginx mp4 module
- Fedora 40 update for nginx, nginx-mod-fancyindex, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts
- Fedora 39 update for nginx, nginx-mod-fancyindex, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts
- openEuler 22.03 LTS SP4 update for nginx
- openEuler 20.03 LTS SP4 update for nginx
- openEuler 22.03 LTS SP1 update for nginx
- openEuler 24.03 LTS update for nginx
- openEuler 22.03 LTS SP3 update for nginx
- Ubuntu update for nginx
- Gentoo update for nginx
- Ubuntu update for nginx
- Ubuntu update for nginx
- cPanel EasyApache update for nginx
- IBM Robotic Process Automation for Cloud Pak update for F5 NGINX Plus and NGINX Open Source
- Multiple vulnerabilities in IBM API Connect
- SUSE update for nginx
- SUSE update for nginx
- Multiple vulnerabilities in IBM Watson Discovery
- Red Hat Enterprise Linux 9 update for the nginx:1.22 module
- Multiple vulnerabilities in Oracle Linux
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Red Hat Enterprise Linux 9 update for nginx
- Red Hat Enterprise Linux 9 update for the nginx:1.22 module
- Red Hat Enterprise Linux 9 update for nginx
- Multiple vulnerabilities in IBM Integrated Analytics System
- Juniper Session Smart Router update for third-party components
- Tenable Sensor Proxy update for third-party components