Release Info

Advisory: CLSA-2022:1669065389

OS: CentOS 8.5 ELS

Public date: 2022-11-21 00:00:00

Project: nginx

Version: 1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3

Errata link: https://errata.tuxcare.com/els_os/centos8.5els/CLSA-2022-1669065389.html

Changelog

- CVE-2022-41741: fix memory corruption in the ngx_http_mp4_module - CVE-2022-41742: fix memory disclosure in the ngx_http_mp4_module

Update

Update command: dnf update nginx*

Packages list

nginx-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.x86_64.rpm nginx-all-modules-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.noarch.rpm nginx-filesystem-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.noarch.rpm nginx-mod-http-image-filter-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.x86_64.rpm nginx-mod-http-perl-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.x86_64.rpm nginx-mod-http-xslt-filter-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.x86_64.rpm nginx-mod-mail-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.x86_64.rpm nginx-mod-stream-1.14.1-9.module_el8.5.0+2086+af250afe.tuxcare.els3.x86_64.rpm

CVEs

CVE-2022-41741
CVE-2022-41742