nginx 1.1.x < 1.1.19 / 1.0.x < 1.0.15 A Buffer Overflow Vulnerability

critical Nessus Plugin ID 198223

Synopsis

The remote web server is affected by a buffer overflow vulnerability.

Description

The installed version of nginx is 1.0.x prior to 1.0.15 or 1.1.x prior to 1.1.19. It is, therefore, affected by the following issue:

- Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file. (CVE-2012-2089)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to nginx 1.0.15 or 1.1.19 or later.

See Also

http://nginx.org/download/patch.2012.mp4.txt

https://mailman.nginx.org/pipermail/nginx-announce/2012/000080.html

https://www.cve.org/CVERecord?id=CVE-2012-2089

Plugin Details

Severity: Critical

ID: 198223

File Name: nginx-CVE-2012-2089.nasl

Version: 1.2

Type: Combined

Agent: unix

Family: Web Servers

Published: 5/31/2024

Updated: 7/17/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.73

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2012-2089

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:nginx:nginx

Required KB Items: Settings/ParanoidReport, installed_sw/nginx

Exploit Ease: No known exploits are available

Patch Publication Date: 4/12/2012

Vulnerability Publication Date: 4/12/2012

Reference Information

CVE: CVE-2012-2089