Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 15 Mar 2012 17:37:29 +0400
From: Andrew Alexeev <andrew@...nx.com>
To: oss-security@...ts.openwall.com
Subject: CVE Request: nginx fix for malformed HTTP responses from upstream servers

Hello,

The nginx team has released stable version 1.0.14, and development
version 1.1.17 of nginx web server, which include a fix for malformed
HTTP responses from upstream servers:

http://trac.nginx.org/nginx/changeset/4535/nginx
http://trac.nginx.org/nginx/changeset/4531/nginx
http://trac.nginx.org/nginx/changeset/4530/nginx

http://nginx.org/en/security_advisories.html

Without this fix contents of previously freed memory might be sent to
a client if an upstream server returned specially crafted response,
potentially resulting in sensitive information leak.

Patch which can be applied to the earlier versions of nginx is here:
http://nginx.org/download/patch.2012.memory.txt

Thanks to Matthew Daley for spotting this one.

-- 
Andrew Alexeev
@nginxorg

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ