Aggiornamento nginx 1.22.1 e 1.23.2 con correzione delle vulnerabilità

È stata rilasciata la versione principale della branch nginx 1.23.2, che continua a sviluppare nuove funzionalità, insieme al rilascio della branch stabile supportata parallelamente, nginx 1.22.1, alla quale vengono apportate solo modifiche relative alla correzione di gravi errori e vulnerabilità.

Nelle nuove versioni sono state risolte due vulnerabilità (CVE-2022-41741, CVE-2022-41742) nel modulo ngx_http_mp4_module, utilizzato per il broadcasting da file nei formati H.264/AAC. Queste vulnerabilità possono provocare danneggiamenti alla memoria o perdite di contenuti in memoria durante l'elaborazione di file mp4 appositamente formattati. Tra le conseguenze si segnala l'arresto anomalo del processo in esecuzione, ma non si escludono altre manifestazioni, come l'esecuzione di codice non autorizzato. server.

È interessante notare che una vulnerabilità simile era già stata risolta nel modulo ngx_http_mp4_module nel 2012. Inoltre, F5 ha segnalato una vulnerabilità simile (CVE-2022-41743) nel prodotto NGINX Plus, riguardante il modulo ngx_http_hls_module, che fornisce supporto per il protocollo HLS (Apple HTTP Live Streaming).

Oltre alla risoluzione delle vulnerabilità, nginx 1.23.2 offre le seguenti modifiche:

  • Support for the variables «$proxy_protocol_tlv_*» has been added, which store the values of the TLV (Type-Length-Value) fields involved in the Type-Length-Value PROXY v2 protocol.
  • Automatic rotation of encryption keys for TLS session tickets has been ensured, applied when using shared memory in the ssl_session_cache directive.
  • The logging level for errors related to incorrect record types SSL, has been lowered from critical to informational level.
  • The logging level for messages about the inability to allocate memory for a new session has been changed from alert to warn and limited to one entry per second.
  • On the Windows platform, a build with OpenSSL 3.0 has been established.
  • Error logging for the PROXY protocol has been set up.
  • The issue has been resolved, due to which the timeout specified in the «ssl_session_timeout» directive did not work when using TLSv1.3 based on OpenSSL or BoringSSL.

Fonte: opennet.ru

Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS 🔥 Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS | ProHoster