version 1.33, 2014/09/06 13:59:35 |
version 1.34, 2014/09/30 22:26:48 |
|
|
A source code patch exists which remedies this problem.</a> |
A source code patch exists which remedies this problem.</a> |
<p> |
<p> |
|
|
|
<li><a name="015_nginx"></a> |
|
<font color="#009000"><strong>015: SECURITY FIX: October 1, 2014</strong></font> |
|
<i>All architectures</i><br> |
|
nginx can reuse cached SSL sessions in unrelated contexts, allowing virtual |
|
host confusion attacks in some configurations. |
|
This issue was assigned CVE-2014-3616. |
|
<br> |
|
<a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.4/common/015_nginx.patch"> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
|
|
</ul> |
</ul> |
|
|
</body> |
</body> |