UbuntuUpdates.org

Package "nginx-naxsi-dbg"

Name: nginx-naxsi-dbg

Description:

nginx web/proxy server (version with naxsi) - debugging symbols

Latest version: 1.4.6-1ubuntu3.9
Release: trusty (14.04)
Level: updates
Repository: universe
Head package: nginx
Homepage: http://nginx.net

Links


Download "nginx-naxsi-dbg"


Other versions of "nginx-naxsi-dbg" in Trusty

Repository Area Version
base universe 1.4.6-1ubuntu3
security universe 1.4.6-1ubuntu3.9

Changelog

Version: 1.4.6-1ubuntu3.4 2016-02-09 20:06:46 UTC

  nginx (1.4.6-1ubuntu3.4) trusty-security; urgency=medium

  * SECURITY UPDATE: multiple resolver security issues (LP: #1538165)
    - debian/patches/CVE-2016-074x-1.patch: fix possible segmentation fault
      on DNS format error.
    - debian/patches/CVE-2016-074x-2.patch: fix crashes in timeout handler.
    - debian/patches/CVE-2016-074x-3.patch: fixed CNAME processing for
      several requests.
    - debian/patches/CVE-2016-074x-4.patch: change the
      ngx_resolver_create_*_query() arguments.
    - debian/patches/CVE-2016-074x-5.patch: fix use-after-free memory
      accesses with CNAME.
    - debian/patches/CVE-2016-074x-6.patch: limited CNAME recursion.
    - CVE-2016-0742
    - CVE-2016-0743
    - CVE-2016-0744

 -- Marc Deslauriers <email address hidden> Wed, 03 Feb 2016 09:12:00 -0500

Source diff to previous version
1538165 Security Issues Impacting NGINX: 1.8.x, 1.9.x
CVE-2016-0742 Invalid pointer dereference might occur during DNS server response processing
CVE-2016-0743 RESERVED
CVE-2016-0744 RESERVED

Version: 1.4.6-1ubuntu3.3 2015-08-07 00:06:52 UTC

  nginx (1.4.6-1ubuntu3.3) trusty-proposed; urgency=medium

  * debian/nginx-common.nginx.init: Fix pidfile extraction, due to multiple
    failure cases, using Debian's solution. (LP: #1314740)

 -- Thomas Ward Wed, 29 Jul 2015 19:43:04 -0400

Source diff to previous version
1314740 [SRU] init script pid parsing has failure cases

Version: 1.4.6-1ubuntu3.2 2015-03-30 01:06:31 UTC

  nginx (1.4.6-1ubuntu3.2) trusty-proposed; urgency=medium

  * d/modules/nginx-http-push: Apply upstream bugfix. (LP: #1216817)
    * src/ngx_http_push_module_setup.c: Modify push module code with
      upstream changes to fix an issue with initialization when using
      `fastcgi_cache` or `proxy_cache`.
    * tests/nginx-cachemanager.conf: (new file) Include upstream change
      of adding an nginx-cachemanager.conf file to the tests.
 -- Thomas Ward <email address hidden> Mon, 09 Feb 2015 12:08:50 -0500

Source diff to previous version
1216817 [SRU] Using `fastcgi_cache` or `proxy_cache` with nginx-extras causes the push module to throw errors.

Version: 1.4.6-1ubuntu3.1 2014-09-22 18:07:19 UTC

  nginx (1.4.6-1ubuntu3.1) trusty-security; urgency=medium

  * SECURITY UPDATE: incorrect cached SSL session reuse (LP: #1370478)
    - debian/patches/CVE-2014-3616.patch: include hash of certificate in
      session id context in src/event/ngx_event_openssl.c.
    - CVE-2014-3616
 -- Marc Deslauriers <email address hidden> Wed, 17 Sep 2014 08:56:46 -0400

1370478 [CVE-2014-3616] \
CVE-2014-3616 reuse cached SSL sessions in unrelated contexts



About   -   Send Feedback to @ubuntu_updates