CVE-2012-2089: F5 Nginx

Medium severity, CVSS 6.8. EPSS: 9.8% chance of exploitation in the next 30 days.

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.

Affected products

  • F5 Nginx: from 1.0.7, up to and including 1.0.14; from 1.1.3, up to and including 1.1.18
  • Fedoraproject Fedora: version 15 only; version 16 only; version 17 only

Published 2012-04-17. Last modified 2026-06-16.