[Bug 1538165] Re: Security Issues Impacting NGINX: 1.8.x, 1.9.x
Launchpad Bug Tracker
1538165 at bugs.launchpad.net
Tue Feb 9 18:00:35 UTC 2016
This bug was fixed in the package nginx - 1.4.6-1ubuntu3.4
---------------
nginx (1.4.6-1ubuntu3.4) trusty-security; urgency=medium
* SECURITY UPDATE: multiple resolver security issues (LP: #1538165)
- debian/patches/CVE-2016-074x-1.patch: fix possible segmentation fault
on DNS format error.
- debian/patches/CVE-2016-074x-2.patch: fix crashes in timeout handler.
- debian/patches/CVE-2016-074x-3.patch: fixed CNAME processing for
several requests.
- debian/patches/CVE-2016-074x-4.patch: change the
ngx_resolver_create_*_query() arguments.
- debian/patches/CVE-2016-074x-5.patch: fix use-after-free memory
accesses with CNAME.
- debian/patches/CVE-2016-074x-6.patch: limited CNAME recursion.
- CVE-2016-0742
- CVE-2016-0743
- CVE-2016-0744
-- Marc Deslauriers <marc.deslauriers at ubuntu.com> Wed, 03 Feb 2016
09:12:00 -0500
--
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to nginx in Ubuntu.
https://bugs.launchpad.net/bugs/1538165
Title:
Security Issues Impacting NGINX: 1.8.x, 1.9.x
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1538165/+subscriptions
More information about the Ubuntu-server-bugs
mailing list