[CLSA-2024:1730478623] Fix CVE(s): CVE-2023-7347, CVE-2024-7347
Type:
security
Severity:
Moderate
Release date:
2024-11-01 16:42:17 UTC
Description:
* SECURITY UPDATE: mp4 module allows buffer underread and unordered chunks - debian/patches/CVE-2024-7347.patch: fix buffer underread while updating stsz atom and reject unordered chunks - CVE-2023-7347
Updated packages:
  • nginx_1.10.3-0ubuntu0.16.04.8+tuxcare.els5_all.deb
    sha:edd0b832e710b156a7a73a568ea31920adf374f7
  • nginx-common_1.10.3-0ubuntu0.16.04.8+tuxcare.els5_all.deb
    sha:d855178d9af4e8cc82d842e9d504b615cf1aa70c
  • nginx-core_1.10.3-0ubuntu0.16.04.8+tuxcare.els5_amd64.deb
    sha:90a2a66f043d8fc7cf1d675ce727a0140d30ec9f
  • nginx-doc_1.10.3-0ubuntu0.16.04.8+tuxcare.els5_all.deb
    sha:5e407870112dde49b3ac1ce35d27fdcc8b490091
  • nginx-extras_1.10.3-0ubuntu0.16.04.8+tuxcare.els5_amd64.deb
    sha:5245bffadfbfb3c017eb313eb0227f8751933bdb
  • nginx-full_1.10.3-0ubuntu0.16.04.8+tuxcare.els5_amd64.deb
    sha:c02a814527f1ef940ca6c0cc7dc2309f02205d5f
  • nginx-light_1.10.3-0ubuntu0.16.04.8+tuxcare.els5_amd64.deb
    sha:e7ebc5322e47f4ba327cab2e8e7545f208310e0e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.