nginx:1.18 security update

エラータID: AXSA:2021-2309:01

Release date: 
Tuesday, August 10, 2021 - 09:01
Subject: 
nginx:1.18 security update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.

Security Fix(es):

* nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name (CVE-2021-23017)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-23017
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

Modularity name: nginx
Stream name: 1.18

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. nginx-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.src.rpm
    MD5: 9bc5e0f2dc7c3a3447825745e5b76664
    SHA-256: f44225441715a34d5c4bc946173b32270fb3d3c41ad245f2657abe1c8ce2375b
    Size: 1.04 MB

Asianux Server 8 for x86_64
  1. nginx-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.x86_64.rpm
    MD5: add45e39cf21e13ed3cfff8c6461275e
    SHA-256: 1189daa712a083115d3bcad144a037d9908b68112f1e339cf1390d1ec0707fad
    Size: 579.29 kB
  2. nginx-all-modules-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.noarch.rpm
    MD5: ad73fdb1e94d1e86f1104b6ca0e5e194
    SHA-256: e38306846bdee0d73b1b64040f6840e1ab05d0446e22f5425ee5e5e539642453
    Size: 23.40 kB
  3. nginx-debugsource-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.x86_64.rpm
    MD5: 6256706d2b068a3537c3d48c9c641507
    SHA-256: f7d531b2a47b71b2077be94dd1151f15ffcb5882e3b7d061df17f80bf292819b
    Size: 669.55 kB
  4. nginx-filesystem-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.noarch.rpm
    MD5: 6a7cd72c2729594ffc8f22423e190450
    SHA-256: a0399e6832ec59aa78a9d8fb3517eca83b151ec7bf3406a50345fd44617098ac
    Size: 24.37 kB
  5. nginx-mod-http-image-filter-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.x86_64.rpm
    MD5: 5b4377d743630665b8e02af412c68e8b
    SHA-256: bccca5d54faf4b1cbcf4033664866cc1a2aa049c5760e55a314053e7e12775ff
    Size: 34.76 kB
  6. nginx-mod-http-perl-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.x86_64.rpm
    MD5: 4ee343641a734e84237484746d4d4b77
    SHA-256: f7bd3a10664a2f442d1eb839320ca2a3cb03b212f4f7458cc12ca260880b57f8
    Size: 46.59 kB
  7. nginx-mod-http-xslt-filter-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.x86_64.rpm
    MD5: 561ff66e997e0f61ea7d9a4b46675e2f
    SHA-256: c6d4850676e9d0cd731955a48a5adeb28eece9dafadcb5917205ce25908bad76
    Size: 33.39 kB
  8. nginx-mod-mail-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.x86_64.rpm
    MD5: 9aac803dbfd8d2a44244bf9a75d75966
    SHA-256: 7c4f84f21897829c1c0f735860dab9c793d1cf981a376f1cbaa01b389e3084c4
    Size: 63.99 kB
  9. nginx-mod-stream-1.18.0-3.module+el8+1282+3f94e401.1.ML.1.x86_64.rpm
    MD5: 8bad26c31f2bd3caa63851b433068959
    SHA-256: de2c1a5f14b176c9e437ef34d672f7be6b6281b21feafed3c1da9e0e71701dc5
    Size: 90.73 kB