NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:f5:nginx:*:*:*:*:plus:*:*:*"
],
"extracted_events": [
{
"introduced": "r22"
},
{
"last_affected": "r27"
}
],
"source": "CPE_RANGE",
"vendor_product": "f5:nginx"
},
{
"cpes": [
"cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.9.0"
},
{
"last_affected": "1.12.4"
},
{
"introduced": "2.0.0"
},
{
"last_affected": "2.4.0"
}
],
"source": "CPE_RANGE",
"vendor_product": "f5:nginx_ingress_controller"
},
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "10.0"
},
{
"last_affected": "10.0"
},
{
"introduced": "11.0"
},
{
"last_affected": "11.0"
}
],
"source": "CPE_STRING",
"vendor_product": "debian:debian_linux"
},
{
"cpes": [
"cpe:2.3:a:f5:nginx:r1:*:*:*:open_source_subscription:*:*:*",
"cpe:2.3:a:f5:nginx:r2:*:*:*:open_source_subscription:*:*:*"
],
"extracted_events": [
{
"introduced": "r1"
},
{
"last_affected": "r1"
},
{
"introduced": "r2"
},
{
"last_affected": "r2"
}
],
"source": "CPE_STRING",
"vendor_product": "f5:nginx"
},
{
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "35"
},
{
"last_affected": "35"
},
{
"introduced": "36"
},
{
"last_affected": "36"
},
{
"introduced": "37"
},
{
"last_affected": "37"
}
],
"source": "CPE_STRING",
"vendor_product": "fedoraproject:fedora"
}
]
}{
"cpe": [
"cpe:2.3:a:f5:nginx:*:*:*:*:open_source:*:*:*",
"cpe:2.3:a:f5:nginx:1.23.0:*:*:*:open_source:*:*:*",
"cpe:2.3:a:f5:nginx:1.23.1:*:*:*:open_source:*:*:*"
],
"extracted_events": [
{
"introduced": "1.1.3"
},
{
"last_affected": "1.22.0"
},
{
"introduced": "1.23.0"
},
{
"last_affected": "1.23.0"
},
{
"introduced": "1.23.1"
},
{
"last_affected": "1.23.1"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}