Release Info

Advisory: CLSA-2022:1669065718

OS: Oracle Linux 6 ELS

Public date: 2022-11-21 00:00:00

Project: nginx

Version: 1.10.3-4.el6.tuxcare.els5

Errata link: https://errata.tuxcare.com/els_os/oraclelinux6els/CLSA-2022-1669065718.html

Changelog

- CVE-2022-41741: fix memory corruption in the ngx_http_mp4_module - CVE-2022-41742: fix memory disclosure in the ngx_http_mp4_module

Update

Update command: yum update nginx*

Packages list

nginx-1.10.3-4.el6.tuxcare.els5.x86_64.rpm nginx-all-modules-1.10.3-4.el6.tuxcare.els5.noarch.rpm nginx-filesystem-1.10.3-4.el6.tuxcare.els5.noarch.rpm nginx-mod-http-geoip-1.10.3-4.el6.tuxcare.els5.x86_64.rpm nginx-mod-http-image-filter-1.10.3-4.el6.tuxcare.els5.x86_64.rpm nginx-mod-http-perl-1.10.3-4.el6.tuxcare.els5.x86_64.rpm nginx-mod-http-xslt-filter-1.10.3-4.el6.tuxcare.els5.x86_64.rpm nginx-mod-mail-1.10.3-4.el6.tuxcare.els5.x86_64.rpm nginx-mod-stream-1.10.3-4.el6.tuxcare.els5.x86_64.rpm

CVEs

CVE-2022-41742
CVE-2022-41741