CVE-2012-2089

Publication date 17 April 2012

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.

Read the notes from the security team

Status

Package Ubuntu Release Status
nginx 11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


jdstrand

only >1.0.7 and >1.1.3 are affected