Security advisory

A patch to fix VU#180064 vulnerability:
http://sysoev.ru/nginx/patch.180065.txt

The patch is not required for 0.8.15, 0.7.62, 0.6.39, and 0.5.38.

All Updated SuSE/OpenSuSE RPMS are beeing built atm and should be
available in 1-2hrs.

Regards

Igor S. wrote:

A patch to fix VU#180064 vulnerability:
http://sysoev.ru/nginx/patch.180065.txt

The patch is not required for 0.8.15, 0.7.62, 0.6.39, and 0.5.38.


InterNetX GmbH
Maximilianstrasse 6
D-93047 Regensburg

Tel. +49 941 59559-480
Fax +49 941 59559-245

Geschäftsführer/CEO: Thomas Mörz
Amtsgericht Regensburg, HRB 7142

A patch to fix VU#180064 vulnerability:
http://sysoev.ru/nginx/patch.180065.txt

The patch is not required for 0.8.15, 0.7.62, 0.6.39, and 0.5.38.

Thank Igor!

I have uploaded 0.8.15 and 0.7.62 to my Ubuntu PPAs:

https://launchpad.net/~jdub/+archive/devel (for 0.8.x)

Jeff Waugh's PPA : Jeff Waugh (for 0.7.x)

Thanks,

  • Jeff

On Mon, Sep 14, 2009 at 05:39:37PM +0400, Igor S. wrote:

A patch to fix VU#180064 vulnerability:
http://sysoev.ru/nginx/patch.180065.txt

The patch is not required for 0.8.15, 0.7.62, 0.6.39, and 0.5.38.

FreeBSD ports tree (www/nginx and www/nginx-devel) are updated.

2009/9/14 Igor S. [email protected]

A patch to fix VU#180064 vulnerability:

uh, VU#180065, u mean?

-jf

On Tue, Sep 15, 2009 at 02:13:31PM +0800, Jeffrey ‘jf’ Lim wrote:

2009/9/14 Igor S. [email protected]

A patch to fix VU#180064 vulnerability:

uh, VU#180065, u mean?

Yes.

On Mon, Sep 14, 2009 at 05:39:37PM +0400, Igor S. wrote:

A patch to fix VU#180064 vulnerability:
http://sysoev.ru/nginx/patch.180065.txt

The patch is not required for 0.8.15, 0.7.62, 0.6.39, and 0.5.38.

Security updates are pushed into the stable Fedora/EPEL repositories

0.7.62 is available for Fedora 10 and Fedora 11
0.6.39 is available for EPEL 4 and EPEL 5

enjoy,

-jeremy