Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nginx | Jul 30, 2024 | Apr 17, 2012 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | Dec 10, 2025 | Apr 16, 2012 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Apr 17, 2012 |
| Nginx | — | Upgrade to nginx version 1.0.15Upgrade to nginx version 1.1.19 | Jan 27, 2014 | Apr 17, 2012 |
| Suse | — | Upgrade nginx-sourceUpgrade nginx | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub