[BACK]Return to errata52.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata52.html between version 1.8 and 1.9

version 1.8, 2013/05/17 11:14:46 version 1.9, 2013/05/22 09:25:47
Line 128 
Line 128 
   
 <li><a name="004_nginx"></a>  <li><a name="004_nginx"></a>
 <font color="#009000"><strong>004: RELIABILITY FIX: May 17, 2013</strong></font> &nbsp; <i>All architectures</i><br>  <font color="#009000"><strong>004: RELIABILITY FIX: May 17, 2013</strong></font> &nbsp; <i>All architectures</i><br>
 A stack-based buffer overflow might occur in an  A problem exists in
 <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=nginx&sektion=8">nginx(8)</a>  <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=nginx&sektion=8">nginx(8)</a>
 worker process while handling a specially crafted request, potentially resulting in arbitrary code  if proxy_pass is used with untrusted HTTP backend servers.
 execution. This issue was assigned CVE-2013-2070.  The problem may lead to a denial of service or a disclosure of a
   worker process memory on a specially crafted response from an
   upstream proxied server.
   This issue was assigned CVE-2013-2070.
   
 <br>  <br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.2/common/004_nginx.patch">  <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.2/common/004_nginx.patch">

Legend:
Removed from v.1.8  
changed lines
  Added in v.1.9