NGINX MP4 module vulnerability
Published Aug 14, 2024
5.7
MEDIUMCVSS 4.0
EPSS 0.32%
Description
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
-
- Version 1.5.13StatusaffectedConstraints<*
- Version
-
- Version R4StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| F5 | NGINX Open Source | n/a |
| ||||||
| F5 | NGINX Plus | n/a |
|
- ≥ 1.5.13 · < 1.26.2
- 1.27.0
- ≥ r27 · < r31
- r31
- r31
- r32
No data.
Red Hat Enterprise Linux 9
nginx-2:1.20.1-22.el9_6.2
Fixed · RHSA-2025:7402
Red Hat Enterprise Linux 9
nginx:1.22-9050020250324053651.9
Fixed · RHSA-2025:3261
Red Hat Enterprise Linux 9
nginx:1.24-9050020250324055038.9
Fixed · RHSA-2025:3262
Red Hat Enterprise Linux 9.2 Extended Update Support
nginx-1:1.20.1-14.el9_2.3
Fixed · RHSA-2025:7546
Red Hat Enterprise Linux 9.2 Extended Update Support
nginx:1.22-9020020250414211356.9
Fixed · RHSA-2025:7548
Red Hat Enterprise Linux 9.4 Extended Update Support
nginx-1:1.20.1-16.el9_4.3
Fixed · RHSA-2025:7619
Red Hat Enterprise Linux 9.4 Extended Update Support
nginx:1.22-9040020250408102234.9
Fixed · RHSA-2025:7549
Red Hat Enterprise Linux 9.4 Extended Update Support
nginx:1.24-9040020250414212413.9
Fixed · RHSA-2025:7542
Red Hat Ansible Automation Platform 1.2
nginx
Will not fix
Red Hat Enterprise Linux 10
nginx
Not affected
Red Hat Enterprise Linux 8
nginx:1.22/nginx
Will not fix
Red Hat Enterprise Linux 8
nginx:1.24/nginx
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | nginx-2:1.20.1-22.el9_6.2 | Fixed | RHSA-2025:7402 |
| Red Hat Enterprise Linux 9 | nginx:1.22-9050020250324053651.9 | Fixed | RHSA-2025:3261 |
| Red Hat Enterprise Linux 9 | nginx:1.24-9050020250324055038.9 | Fixed | RHSA-2025:3262 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | nginx-1:1.20.1-14.el9_2.3 | Fixed | RHSA-2025:7546 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | nginx:1.22-9020020250414211356.9 | Fixed | RHSA-2025:7548 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | nginx-1:1.20.1-16.el9_4.3 | Fixed | RHSA-2025:7619 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | nginx:1.22-9040020250408102234.9 | Fixed | RHSA-2025:7549 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | nginx:1.24-9040020250414212413.9 | Fixed | RHSA-2025:7542 |
| Red Hat Ansible Automation Platform 1.2 | nginx | Will not fix | n/a |
| Red Hat Enterprise Linux 10 | nginx | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.22/nginx | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.24/nginx | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue only affects configurations with the ngx_http_mp4_module module loaded and being used. Additionally, to exploit this flaw, an attacker must be able to send and process a specially crafted MP4 file with the ngx_http_mp4_module module. This module can be disable via the configuration file if its functionality is not needed.
Red Hat mitigation
Restrict publishing of audio and video to trusted users only.
References (8)
- http://www.openwall.com/lists/oss-security/2024/08/14/4 Mailing List
- https://access.redhat.com/security/cve/CVE-2024-7347 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2304966 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48285 Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00017.html
- https://my.f5.com/manage/s/article/K000140529 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-7347
- https://www.cve.org/CVERecord?id=CVE-2024-7347
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2024/08/14/4 | Mailing List | |
| https://access.redhat.com/security/cve/CVE-2024-7347 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2304966 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48285 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2025/03/msg00017.html | ||
| https://my.f5.com/manage/s/article/K000140529 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-7347 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-7347 |
Change history (0)
No recorded changes yet.