CVE-2018-16845 is a medium-severity vulnerability affecting nginx versions prior to 1.15.6 and 1.14.1, specifically when built with the ngx_http_mp4_module and configured to process MP4 files. An attacker can exploit this by providing a specially crafted MP4 file, leading to an infinite loop, worker process crash, or memory disclosure. The attack requires local access, user interaction, and low attack complexity. While not actively exploited in the wild and lacking public exploit code, it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.7, <= 1.0.15CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
>= 1.1.3, <= 1.15.5CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
nginx: Denial of service and memory disclosure via mp4 module
Nov 6, 2018Memory disclosure in the ngx_http_mp4_module
Jan 1, 2018Memory disclosure in the ngx_http_mp4_module
Jan 1, 2018Memory disclosure in the ngx_http_mp4_module
Jan 1, 2018Memory disclosure in the ngx_http_mp4_module
Jan 1, 2018Memory disclosure in the ngx_http_mp4_module
Jan 1, 2018Memory disclosure in the ngx_http_mp4_module
Memory disclosure in the ngx_http_mp4_module
Memory disclosure in the ngx_http_mp4_module