nginx fix for malformed HTTP responses from upstream servers
- From: security-bulletin@xxxxxxxxx
- Date: Thu, 15 Mar 2012 17:48:47 +0400 (MSK)
Hello,
The nginx team has released stable version 1.0.14, and development
version 1.1.17 of nginx web server, which include a fix for malformed
HTTP responses from upstream servers:
http://trac.nginx.org/nginx/changeset/4535/nginx
http://trac.nginx.org/nginx/changeset/4531/nginx
http://trac.nginx.org/nginx/changeset/4530/nginx
http://nginx.org/en/security_advisories.html
Without this fix contents of previously freed memory might be sent to
a client if an upstream server returned specially crafted response,
potentially resulting in sensitive information leak.
Patch which can be applied to the earlier versions of nginx is here:
http://nginx.org/download/patch.2012.memory.txt
Thanks to Matthew Daley for spotting this one.
-- nginx team
- Prev by Date: Re: Android wireless accepts fake response (No interaction requires) (Vulnerability ?)
- Next by Date: WikyBlog 1.7.3RC2 XSS vulnerability
- Previous by thread: Oracle Exadata Infiniband Switch default logins and world readable shadow file
- Next by thread: WikyBlog 1.7.3RC2 XSS vulnerability
- Index(es):