diff xml/en/security_advisories.xml @ 2898:0b7e004b5061

nginx-1.23.2, nginx-1.22.1
author Maxim Dounin <mdounin@mdounin.ru>
date Wed, 19 Oct 2022 11:26:47 +0300
parents 0456ea786ef6
children f961e8a01053
line wrap: on
line diff
--- a/xml/en/security_advisories.xml	Tue Oct 18 11:56:15 2022 +0100
+++ b/xml/en/security_advisories.xml	Wed Oct 19 11:26:47 2022 +0300
@@ -24,6 +24,22 @@
 
 <security>
 
+<item name="Memory corruption in the ngx_http_mp4_module"
+      severity="medium"
+      cve="2022-41741"
+      good="1.23.2+, 1.22.1+"
+      vulnerable="1.1.3-1.23.1, 1.0.7-1.0.15">
+<patch name="patch.2022.mp4.txt" />
+</item>
+
+<item name="Memory disclosure in the ngx_http_mp4_module"
+      severity="medium"
+      cve="2022-41742"
+      good="1.23.2+, 1.22.1+"
+      vulnerable="1.1.3-1.23.1, 1.0.7-1.0.15">
+<patch name="patch.2022.mp4.txt" />
+</item>
+
 <item name="1-byte memory overwrite in resolver"
       severity="medium"
       advisory="http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html"