Release Info

Advisory: CLSA-2022:1669065608

OS: Ubuntu 16.04 ELS

Public date: 2022-11-21 00:00:00

Project: nginx

Version: 1.10.3-0ubuntu0.16.04.8+tuxcare.els3

Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2022-1669065608.html

Changelog

* SECURITY UPDATE: memory corruption and disclosure in MP4 streaming module - debian/patches/CVE-2022-41741-CVE-2022-41742.patch: disable duplicated atoms and ensure that (the most of them) appeared once in a container. - CVE-2022-41741 - CVE-2022-41742

Update

Update command: apt-get update apt-get --only-upgrade install nginx*

Packages list

nginx_1.10.3-0ubuntu0.16.04.8+tuxcare.els3_all.deb nginx-common_1.10.3-0ubuntu0.16.04.8+tuxcare.els3_all.deb nginx-core_1.10.3-0ubuntu0.16.04.8+tuxcare.els3_amd64.deb nginx-doc_1.10.3-0ubuntu0.16.04.8+tuxcare.els3_all.deb nginx-extras_1.10.3-0ubuntu0.16.04.8+tuxcare.els3_amd64.deb nginx-full_1.10.3-0ubuntu0.16.04.8+tuxcare.els3_amd64.deb nginx-light_1.10.3-0ubuntu0.16.04.8+tuxcare.els3_amd64.deb

CVEs

CVE-2022-41741
CVE-2022-41742