UbuntuUpdates.org

Package "nginx"

Name: nginx

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • PAM authentication module for Nginx
  • Purge content from Nginx caches
  • WebDAV missing commands support for Nginx
  • Bring echo and more shell style goodies to Nginx

Latest version: 1.14.0-0ubuntu1.2
Release: bionic (18.04)
Level: updates
Repository: universe

Links

Save this URL for the latest version of "nginx": https://www.ubuntuupdates.org/nginx



Other versions of "nginx" in Bionic

Repository Area Version
base universe 1.14.0-0ubuntu1
base main 1.14.0-0ubuntu1
security universe 1.14.0-0ubuntu1.2
security main 1.14.0-0ubuntu1.2
updates main 1.14.0-0ubuntu1.2
PPA: Nginx 1.14.1-0+bionic0

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.14.0-0ubuntu1.2 2018-11-07 17:07:19 UTC

  nginx (1.14.0-0ubuntu1.2) bionic-security; urgency=medium

  * SECURITY UPDATE: excessive memory consumption in HTTP/2 implementation
    - debian/patches/CVE-2018-16843.patch: add flood detection in
      src/http/v2/ngx_http_v2.c, src/http/v2/ngx_http_v2.h.
    - CVE-2018-16843
  * SECURITY UPDATE: excessive CPU usage in HTTP/2 implementation
    - debian/patches/CVE-2018-16844.patch: limit the number of idle state
      switches in src/http/v2/ngx_http_v2.c, src/http/v2/ngx_http_v2.h.
    - CVE-2018-16844
  * SECURITY UPDATE: infinite loop in ngx_http_mp4_module
    - debian/patches/CVE-2018-16845.patch: fixed reading 64-bit atoms in
      src/http/modules/ngx_http_mp4_module.c.
    - CVE-2018-16845

 -- Marc Deslauriers <email address hidden> Tue, 06 Nov 2018 13:54:15 -0500

Source diff to previous version
CVE-2018-16843 Excessive memory usage in HTTP/2
CVE-2018-16844 Excessive CPU usage in HTTP/2
CVE-2018-16845 Memory disclosure in the ngx_http_mp4_module

Version: 1.14.0-0ubuntu1.1 2018-09-20 09:06:59 UTC

  nginx (1.14.0-0ubuntu1.1) bionic; urgency=medium

  * Stable Release Update. Do not attempt to start nginx if other daemon
    is binding to port 80, to prevent install failure (LP: #1782226):
    - d/nginx{core,light,full,extras}.postinst: Add checks for whether
      port 80 is in use or not to determine whether or not to attempt
      starting of the NGINX service during install/upgrade.
    - d/control: Add dependencies to nginx-{core,light,full,extras} on
      `iproute2` as the postinst scripts now use `ss` to determine if
      Port 80 is open or not.

 -- Andres Rodriguez <email address hidden> Mon, 20 Aug 2018 18:41:42 -0400

1782226 [SRU] Allow NGINX to install but not start during postinst if another process is bound to port 80



About   -   Send Feedback to @ubuntu_updates