<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>[nginx-announce] security advisory</title>
<description>Hello!
Matthew Daley discovered a security problem in the 
ngx_http_mp4_module, CVE-2012-2089.
A specially crafted mp4 file might allow to overwrite memory 
locations in a worker process if the ngx_http_mp4_module is 
used, potentially resulting in arbitrary code execution.
The problem affects nginx 1.1.3+, 1.0.7+ built with the 
ngx_http_mp4_module (the module is not built by default) and 
the &amp;quot;mp4&amp;quot; directive is used in a configuration file.
The problem is fixed in 1.1.19, 1.0.15.
Patch for the problem can be found here:
http://nginx.org/download/patch.2012.mp4.txt
Maxim Dounin
_______________________________________________
nginx-announce mailing list
nginx-announce@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-announce</description><link>http://forum.nginx.org/read.php?27,225232,225232#msg-225232</link><lastBuildDate>Tue, 21 May 2013 16:17:49 -0400</lastBuildDate>
<generator>Phorum 5.2.16</generator>
<item>
<guid>http://forum.nginx.org/read.php?27,225232,225232#msg-225232</guid>
<title>[nginx-announce] security advisory</title><link>http://forum.nginx.org/read.php?27,225232,225232#msg-225232</link><description><![CDATA[Hello!<br /><br />Matthew Daley discovered a security problem in the<br />ngx_http_mp4_module, CVE-2012-2089.<br /><br />A specially crafted mp4 file might allow to overwrite memory<br />locations in a worker process if the ngx_http_mp4_module is<br />used, potentially resulting in arbitrary code execution.<br /><br />The problem affects nginx 1.1.3+, 1.0.7+ built with the<br />ngx_http_mp4_module (the module is not built by default) and<br />the &quot;mp4&quot; directive is used in a configuration file.<br /><br />The problem is fixed in 1.1.19, 1.0.15.<br /><br />Patch for the problem can be found here:<br /><br />http://nginx.org/download/patch.2012.mp4.txt<br /><br />Maxim Dounin<br /><br />_______________________________________________<br />nginx-announce mailing list<br />nginx-announce@nginx.org<br />http://mailman.nginx.org/mailman/listinfo/nginx-announce]]></description>
<dc:creator>Maxim Dounin</dc:creator>
<category>Nginx Announcements - English</category><pubDate>Thu, 12 Apr 2012 09:30:00 -0400</pubDate></item>
</channel>
</rss>