ELSA-2023-5713

ELSA-2023-5713 - nginx:1.22 security update

Type:SECURITY
Impact:MODERATE
Release Date:2023-10-17

Description


[1:1.22.1-1.0.1.1]
- Resolves: RHEL-12728 - nginx:1.22/nginx: HTTP/2: Multiple HTTP/2 enabled web
servers are vulnerable to a DDoS attack (Rapid Reset Attack)(CVE-2023-44487)


Related CVEs


CVE-2023-44487

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) nginx-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.src.rpm1acf2984bbf93fbc92c0fb9bb278fd7e2af72d9005a575ef4eca5b2f540f5d08-ol8_aarch64_appstream
nginx-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.aarch64.rpm7f448febb51873cc3a2c8b857d9bb72a9fe554404bd208ea164355dab5fc863c-ol8_aarch64_appstream
nginx-all-modules-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.noarch.rpm54bdc330c62c9bff0c0e01154f7d58222dbe91fa769cc73bff02035df3e050f0-ol8_aarch64_appstream
nginx-filesystem-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.noarch.rpm95e1b889659e7829f2052d1a32e20f4d8618985b0584b11c8b534386c6bc54bc-ol8_aarch64_appstream
nginx-mod-devel-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.aarch64.rpmbbc100ce14f0071423b845f78a2ba85859b234ef5e24af2ac4f212fe78007d54-ol8_aarch64_appstream
nginx-mod-http-image-filter-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.aarch64.rpm73ebbd73bd5f04fa288d5a4308ce645915d8880441dd9b5d66577c43ad9c46a0-ol8_aarch64_appstream
nginx-mod-http-perl-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.aarch64.rpm01d1dbb78c582919e7e29ea2099fcfca6d85f63138105207a103b85db009f29c-ol8_aarch64_appstream
nginx-mod-http-xslt-filter-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.aarch64.rpm35cce0142239d6024a9e1053cb3fe1fcf1f4b0f47124de42189e8b50b888d9ea-ol8_aarch64_appstream
nginx-mod-mail-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.aarch64.rpm4a91cbaaac0c8f0e91e44220da0a4be7e6223b2dabda2de5eeda7246065121c5-ol8_aarch64_appstream
nginx-mod-stream-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.aarch64.rpm230f615c2ffb2ec416393a8bbbd5e43fcbde90ea5c9b7f26d343abcad6ca01d4-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) nginx-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.src.rpm1acf2984bbf93fbc92c0fb9bb278fd7e2af72d9005a575ef4eca5b2f540f5d08-ol8_x86_64_appstream
nginx-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpm718e210b09ecc944cbf7de6049d4779abb969668097eefa66b17231a41ca84d8-exadata_dbserver_24.1.3.0.0_x86_64_base
nginx-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpm718e210b09ecc944cbf7de6049d4779abb969668097eefa66b17231a41ca84d8-exadata_dbserver_24.1.4.0.0_x86_64_base
nginx-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpm718e210b09ecc944cbf7de6049d4779abb969668097eefa66b17231a41ca84d8-ol8_x86_64_appstream
nginx-all-modules-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.noarch.rpm54bdc330c62c9bff0c0e01154f7d58222dbe91fa769cc73bff02035df3e050f0-ol8_x86_64_appstream
nginx-filesystem-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.noarch.rpm95e1b889659e7829f2052d1a32e20f4d8618985b0584b11c8b534386c6bc54bc-ol8_x86_64_appstream
nginx-mod-devel-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpm877f5f421ae1cf520550539e4adb5f19b016b606e50780d57468b5b82b2e7863-ol8_x86_64_appstream
nginx-mod-http-image-filter-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpma6c495ad902f981a92825bea515f7ce1a50ea9d36d83e96752696c0d57e9cdbc-ol8_x86_64_appstream
nginx-mod-http-perl-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpmdfd2dd212f9689da8d39e81d83cc19c1e44f6def64f64a414b84affa04fefb6a-ol8_x86_64_appstream
nginx-mod-http-xslt-filter-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpmc7bc97741fbd661951fef9555b3646125f3aa07c61c6ab99c3a909ade52f0854-ol8_x86_64_appstream
nginx-mod-mail-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpm4e370754b5ab2e0c5367bc8d84651ab625935fc03eb10348c368a67e6b6b0d77-ol8_x86_64_appstream
nginx-mod-stream-1.22.1-1.0.1.module+el8.8.0+21180+f87487ef.1.x86_64.rpm01384ad4d65ac4c9d938f050e9ba57d33a88f565179ea60b4a3ff00572b4cbb6-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete