UbuntuUpdates.org

Package "libnginx-mod-http-image-filter"

Name: libnginx-mod-http-image-filter

Description:

HTTP image filter module for Nginx

Latest version: 1.14.0-0ubuntu1.7
Release: bionic (18.04)
Level: updates
Repository: main
Head package: nginx
Homepage: http://nginx.net

Links


Download "libnginx-mod-http-image-filter"


Other versions of "libnginx-mod-http-image-filter" in Bionic

Repository Area Version
base main 1.14.0-0ubuntu1
security main 1.14.0-0ubuntu1.7
PPA: Nginx 1.16.1-0+bionic1

Changelog

Version: 1.14.0-0ubuntu1.7 2020-01-13 17:06:52 UTC

  nginx (1.14.0-0ubuntu1.7) bionic-security; urgency=medium

  * SECURITY UPDATE: request smuggling via error_page
    - debian/patches/CVE-2019-20372.patch: discard request body when
      redirecting to a URL via error_page in
      src/http/ngx_http_special_response.c.
    - CVE-2019-20372

 -- Marc Deslauriers <email address hidden> Fri, 10 Jan 2020 14:18:38 -0500

Source diff to previous version
CVE-2019-20372 NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read una

Version: 1.14.0-0ubuntu1.6 2019-08-20 16:06:33 UTC

  nginx (1.14.0-0ubuntu1.6) bionic-security; urgency=medium

  * No change rebuild in -security pocket now that OpenSSL 1.1.1 is
    available.

 -- Marc Deslauriers <email address hidden> Tue, 20 Aug 2019 08:46:02 -0400

Source diff to previous version

Version: 1.14.0-0ubuntu1.5 2019-08-16 13:07:17 UTC

  nginx (1.14.0-0ubuntu1.5) bionic; urgency=medium

  * No change rebuild for bionic outside of security pocket to pick up
    OpenSSL 1.1.1. (LP: #1840404)

 -- Marc Deslauriers <email address hidden> Fri, 16 Aug 2019 07:05:57 -0400

Source diff to previous version
1840404 [regression] 1.14.0-0ubuntu1.4 security update enables TLS1.3 without a choice

Version: 1.14.0-0ubuntu1.4 2019-08-15 18:07:40 UTC

  nginx (1.14.0-0ubuntu1.4) bionic-security; urgency=medium

  * SECURITY UPDATE: HTTP/2 Data Dribble issue
    - debian/patches/CVE-2019-9511.patch: limited number of DATA frames in
      src/http/v2/ngx_http_v2.c, src/http/v2/ngx_http_v2.h,
      src/http/v2/ngx_http_v2_filter_module.c.
    - CVE-2019-9511
  * SECURITY UPDATE: HTTP/2 Resource Loop / Priority Shuffling issue
    - debian/patches/CVE-2019-9513.patch: limited number of PRIORITY frames
      in src/http/v2/ngx_http_v2.c, src/http/v2/ngx_http_v2.h.
    - CVE-2019-9513
  * SECURITY UPDATE: HTTP/2 0-Length Headers Leak issue
    - debian/patches/CVE-2019-9516.patch: reject zero length headers with
      PROTOCOL_ERROR in src/http/v2/ngx_http_v2.c.
    - CVE-2019-9516

 -- Marc Deslauriers <email address hidden> Wed, 14 Aug 2019 14:44:40 -0400

Source diff to previous version
CVE-2019-9511 Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser
CVE-2019-9513 Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request strea
CVE-2019-9516 Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with

Version: 1.14.0-0ubuntu1.3 2019-07-22 10:06:16 UTC

  nginx (1.14.0-0ubuntu1.3) bionic; urgency=medium

  * No changes rebuild (to build against OpenSSL 1.1.1 in Bionic)
    (LP: #1836366)

 -- Thomas Ward <email address hidden> Fri, 12 Jul 2019 14:18:43 -0400

1836366 [SRU] No Changes Rebuild in Bionic for OpenSSL compat reasons



About   -   Send Feedback to @ubuntu_updates