Executive Summary

Titlenginx security update
NameDSA-4335First vendor Publication2018-11-08
VendorDebianLast vendor Modification2018-11-08
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score7.8Attack RangeNetwork
Cvss Impact Score6.9Attack ComplexityLow
Cvss Expoit Score10AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores


Three vulnerabilities were discovered in Nginx, a high-performance web and reverse proxy server, which could in denial of service in processing HTTP/2 (via excessive memory/CPU usage) or server memory disclosure in the ngx_http_mp4_module module (used for server-side MP4 streaming).

For the stable distribution (stretch), these problems have been fixed in version 1.10.3-1+deb9u2.

We recommend that you upgrade your nginx packages.

For the detailed security status of nginx please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nginx

Original Source

Url : http://www.debian.org/security/2018/dsa-4335

CWE : Common Weakness Enumeration

67 %CWE-400Uncontrolled Resource Consumption ('Resource Exhaustion')
33 %CWE-200Information Exposure

CPE : Common Platform Enumeration


Nessus® Vulnerability Scanner

2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-7c540fdab4.nasl - Type : ACT_GATHER_INFO
2018-12-17Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2018-1125.nasl - Type : ACT_GATHER_INFO
2018-12-10Name : The remote EulerOS host is missing multiple security updates.
File : EulerOS_SA-2018-1399.nasl - Type : ACT_GATHER_INFO
2018-11-14Name : The remote web server is affected by multiple vulnerabilities.
File : nginx_1_15_6.nasl - Type : ACT_GATHER_INFO
2018-11-09Name : The remote Debian host is missing a security update.
File : debian_DLA-1572.nasl - Type : ACT_GATHER_INFO
2018-11-09Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4335.nasl - Type : ACT_GATHER_INFO
2018-11-07Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_84ca56bee1de11e8bcfd00e04c1ea73d.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
2018-12-13 00:21:17
  • Multiple Updates
2018-11-09 00:18:56
  • First insertion