---
title: "CVE-2018-16845"
canonical: "https://kb.cynergy.app/space/MD/899252819/CVE-2018-16845"
format: markdown
---
**Description:**

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

**Published On:**

2018-11-06

**Updated On:**

2022-02-22

**Trending:**

FALSE

**CWE:**

CWE-400

**Mitigation:**

![image](media://50f7695d-ec29-4638-a5fb-79a5a7ff53ec)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| HT212818 | apple | Fixed in Xcode 13 | IDE Xcode Server<br />&nbsp; &nbsp; &nbsp; &nbsp; Impact: Multiple issues in nginx <br />&nbsp; &nbsp; &nbsp; &nbsp; Description: Multiple issues were addressed by updating nginx to version 1.21.0. <br />&nbsp; &nbsp; &nbsp; &nbsp; Available for: macOS Big Sur 11.3 and later <br />Installation note:<br>Xcode 13 may be obtained from:<br>[https://developer.apple.com/xcode/downloads/](https://developer.apple.com/xcode/downloads/)<br>To check that the Xcode has been updated:<br>- Select Xcode in the menu bar
- Select About Xcode
- The version after applying this update will be "Xcode 13".<br><br /> | 2022-02-20 | [https://support.apple.com/en-us/HT212818](https://support.apple.com/en-us/HT212818) |
| openSUSE-SU-2019:0195-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>nginx was updated to 1.14.2:<br>- Bugfix: nginx could not be built on Fedora 28 Linux.
- Bugfix: in handling of client addresses when using unix domain<br>listen sockets to work with datagrams on Linux.<br>- Change: the logging level of the 'http request', 'https proxy<br>request', 'unsupported protocol', 'version too low',  
  'no suitable key share', and 'no suitable signature algorithm'  
  SSL errors has been lowered from 'crit' to 'info'.<br>- Bugfix: when using OpenSSL 1.1.0 or newer it was not possible<br>to switch off 'ssl_prefer_server_ciphers' in a virtual server  
  if it was switched on in the default server.<br>- Bugfix: nginx could not be built with LibreSSL 2.8.0.
- Bugfix: if nginx was built with OpenSSL 1.1.0 and used with<br>OpenSSL 1.1.1, the TLS 1.3 protocol was always enabled.<br>- Bugfix: sending a disk-buffered request body to a gRPC backend<br>might fail.<br>- Bugfix: connections with some gRPC backends might not be cached when<br>using the 'keepalive' directive.<br>- Bugfix: a segmentation fault might occur in a worker process if the<br>ngx_http_mp4_module was used on 32-bit platforms.<br>Changes with nginx 1.14.1:<br>- Security: when using HTTP/2 a client might cause excessive memory<br>consumption (CVE-2018-16843) and CPU usage (CVE-2018-16844).<br>- Security: processing of a specially crafted mp4 file with the<br>ngx_http_mp4_module might result in worker process memory disclosure  
  (CVE-2018-16845).<br>- Bugfix: working with gRPC backends might result in excessive memory<br>consumption.<br>Changes with nginx 1.13.12:<br>- Bugfix: connections with gRPC backends might be closed unexpectedly<br>when returning a large response.<br>Changes with nginx 1.13.10<br>- Feature: the 'set' parameter of the 'include' SSI<br>directive now allows writing arbitrary responses to a  
  variable; the 'subrequest_output_buffer_size' directive  
  defines maximum response size.<br>- Feature: now nginx uses clock_gettime(CLOCK_MONOTONIC) if available,<br>to avoid timeouts being incorrectly triggered on system time changes.<br>- Feature: the 'escape=none' parameter of the 'log_format' directive.<br>Thanks to Johannes Baiter and Calin Don.<br>- Feature: the $ssl_preread_alpn_protocols variable in the<br>ngx_stream_ssl_preread_module.<br>- Feature: the ngx_http_grpc_module.
- Bugfix: in memory allocation error handling in the 'geo' directive.
- Bugfix: when using variables in the 'auth_basic_user_file' directive<br>a null character might appear in logs.  
  Thanks to Vadim Filimonov. | 2019-03-20 | [http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00036.html](http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00036.html) |
| openSUSE-SU-2019:2120-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).
- CVE-2018-16845: Fixed denial of service and memory disclosure via mp4 module (bsc#1115015).
- CVE-2018-16843: Fixed excessive memory consumption in HTTP/2 implementation (bsc#1115022).
- CVE-2018-16844: Fixed excessive CPU usage via flaw in HTTP/2 implementation (bsc#1115025).<br>This update was imported from the SUSE:SLE-15-SP1:Update update project. | 2019-09-11 | [http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html) |
| RHSA-2018:3652 | redhat | Red Hat Security Advisory: rh-nginx18-nginx security update | An update for rh-nginx18-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-02-19 | [https://access.redhat.com/errata/RHSA-2018:3652](https://access.redhat.com/errata/RHSA-2018:3652) |
| RHSA-2018:3653 | redhat | Red Hat Security Advisory: rh-nginx110-nginx security update | An update for rh-nginx110-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-02-19 | [https://access.redhat.com/errata/RHSA-2018:3653](https://access.redhat.com/errata/RHSA-2018:3653) |
| RHSA-2018:3680 | redhat | Red Hat Security Advisory: rh-nginx112-nginx security update | An update for rh-nginx112-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-02-19 | [https://access.redhat.com/errata/RHSA-2018:3680](https://access.redhat.com/errata/RHSA-2018:3680) |
| RHSA-2018:3681 | redhat | Red Hat Security Advisory: rh-nginx114-nginx security update | An update for rh-nginx114-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-02-19 | [https://access.redhat.com/errata/RHSA-2018:3681](https://access.redhat.com/errata/RHSA-2018:3681) |
| FEDORA-2018-7c540fdab4 | fedora | Fedora 29 Update: nginx-1.14.1-2.fc29 | Security fix for CVE-2018-16843, CVE-2018-16844, CVE-2018-16845 + nginx rebase  
to 1.14.1.  ----  New version 1.14.1 | 2019-02-19 | [https://bodhi.fedoraproject.org/updates/FEDORA-2018-7c540fdab4](https://bodhi.fedoraproject.org/updates/FEDORA-2018-7c540fdab4) |
| APPLE-SA-2021-09-20-4 | apple | APPLE-SA-2021-09-20-4 Xcode 13 |  | 2021-09-21 | [https://lists.apple.com/archives/security-announce/2021/Sep/msg00008.html](https://lists.apple.com/archives/security-announce/2021/Sep/msg00008.html) |
| openSUSE-SU-2019:0195-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>nginx was updated to 1.14.2:<br>- Bugfix: nginx could not be built on Fedora 28 Linux.
- Bugfix: in handling of client addresses when using unix domain<br>listen sockets to work with datagrams on Linux.<br>- Change: the logging level of the 'http request', 'https proxy<br>request', 'unsupported protocol', 'version too low',  
  'no suitable key share', and 'no suitable signature algorithm'  
  SSL errors has been lowered from 'crit' to 'info'.<br>- Bugfix: when using OpenSSL 1.1.0 or newer it was not possible<br>to switch off 'ssl_prefer_server_ciphers' in a virtual server  
  if it was switched on in the default server.<br>- Bugfix: nginx could not be built with LibreSSL 2.8.0.
- Bugfix: if nginx was built with OpenSSL 1.1.0 and used with<br>OpenSSL 1.1.1, the TLS 1.3 protocol was always enabled.<br>- Bugfix: sending a disk-buffered request body to a gRPC backend<br>might fail.<br>- Bugfix: connections with some gRPC backends might not be cached when<br>using the 'keepalive' directive.<br>- Bugfix: a segmentation fault might occur in a worker process if the<br>ngx_http_mp4_module was used on 32-bit platforms.<br>Changes with nginx 1.14.1:<br>- Security: when using HTTP/2 a client might cause excessive memory<br>consumption (CVE-2018-16843) and CPU usage (CVE-2018-16844).<br>- Security: processing of a specially crafted mp4 file with the<br>ngx_http_mp4_module might result in worker process memory disclosure  
  (CVE-2018-16845).<br>- Bugfix: working with gRPC backends might result in excessive memory<br>consumption.<br>Changes with nginx 1.13.12:<br>- Bugfix: connections with gRPC backends might be closed unexpectedly<br>when returning a large response.<br>Changes with nginx 1.13.10<br>- Feature: the 'set' parameter of the 'include' SSI<br>directive now allows writing arbitrary responses to a  
  variable; the 'subrequest_output_buffer_size' directive  
  defines maximum response size.<br>- Feature: now nginx uses clock_gettime(CLOCK_MONOTONIC) if available,<br>to avoid timeouts being incorrectly triggered on system time changes.<br>- Feature: the 'escape=none' parameter of the 'log_format' directive.<br>Thanks to Johannes Baiter and Calin Don.<br>- Feature: the $ssl_preread_alpn_protocols variable in the<br>ngx_stream_ssl_preread_module.<br>- Feature: the ngx_http_grpc_module.
- Bugfix: in memory allocation error handling in the 'geo' directive.
- Bugfix: when using variables in the 'auth_basic_user_file' directive<br>a null character might appear in logs.  
  Thanks to Vadim Filimonov. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00036.html](https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00036.html) |
| openSUSE-SU-2019:2120-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).
- CVE-2018-16845: Fixed denial of service and memory disclosure via mp4 module (bsc#1115015).
- CVE-2018-16843: Fixed excessive memory consumption in HTTP/2 implementation (bsc#1115022).
- CVE-2018-16844: Fixed excessive CPU usage via flaw in HTTP/2 implementation (bsc#1115025).<br>This update was imported from the SUSE:SLE-15-SP1:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html](https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html) |
| usn-3812-1 | canonical | nginx vulnerabilities | It was discovered that nginx incorrectly handled the HTTP/2 implementation.  
A remote attacker could possibly use this issue to cause excessive memory  
consumption, leading to a denial of service. This issue only affected  
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)  
Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2  
implementation. A remote attacker could possibly use this issue to cause  
excessive CPU usage, leading to a denial of service. This issue only  
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.  
(CVE-2018-16844)  
It was discovered that nginx incorrectly handled the ngx_http_mp4_module  
module. A remote attacker could possibly use this issue with a specially  
crafted mp4 file to cause nginx to crash, stop responding, or access  
arbitrary memory. (CVE-2018-16845) | 2020-07-29 | [https://ubuntu.com/security/notices/USN-3812-1](https://ubuntu.com/security/notices/USN-3812-1) |
| SUSE-SU-2019:0334-1 | suse | Security update for nginx | This update for nginx to version 1.14.2 fixes the following issues:<br>Security vulnerabilities addressed:<br>- CVE-2018-16843 CVE-2018-16844: Fixed an issue whereby a client using HTTP/2<br>might cause excessive memory consumption and CPU usage (bsc#1115025 bsc#1115022).<br>- CVE-2018-16845: Fixed an issue which might result in worker process memory<br>disclosure whne processing of a specially crafted mp4 file with the  
  ngx_http_mp4_module (bsc#1115015).<br>Other bug fixes and changes made:<br>- Fixed an issue with handling of client addresses when using unix domain<br>listen sockets to work with datagrams on Linux.<br>- The logging level of the 'http request', 'https proxy request',<br>'unsupported protocol', 'version too low', 'no suitable key share', and  
  'no suitable signature algorithm' SSL errors has been lowered from 'crit' to  
  'info'.<br>- Fixed an issue with using OpenSSL 1.1.0 or newer it was not possible<br>to switch off 'ssl_prefer_server_ciphers' in a virtual server  
  if it was switched on in the default server.<br>- Fixed an issue with TLS 1.3 always being enabled when built with OpenSSL<br>1.1.0 and used with 1.1.1<br>- Fixed an issue with sending a disk-buffered request body to a gRPC backend
- Fixed an issue with connections of some gRPC backends might not be cached when<br>using the 'keepalive' directive.<br>- Fixed a segmentation fault, which might occur in a worker process if the<br>ngx_http_mp4_module was used on 32-bit platforms.<br>- Fixed an issue, whereby working with gRPC backends might result in excessive<br>memory consumption. | 2019-03-20 | [https://www.suse.com/support/update/announcement/2019/suse-su-20190334-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20190334-1/) |
| SUSE-SU-2019:2309-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).
- CVE-2018-16845: Fixed denial of service and memory disclosure via mp4 module (bsc#1115015).
- CVE-2018-16843: Fixed excessive memory consumption in HTTP/2 implementation (bsc#1115022).
- CVE-2018-16844: Fixed excessive CPU usage via flaw in HTTP/2 implementation (bsc#1115025). | 2019-09-06 | [https://www.suse.com/support/update/announcement/2019/suse-su-20192309-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20192309-1/) |