=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata55.html,v retrieving revision 1.22 retrieving revision 1.23 diff -c -r1.22 -r1.23 *** www/errata55.html 2014/09/06 13:59:35 1.22 --- www/errata55.html 2014/09/30 19:44:30 1.23 *************** *** 191,196 **** --- 191,207 ---- A source code patch exists which remedies this problem.

+

  • + 011: SECURITY FIX: October 1, 2014 +   All architectures
    + nginx can reuse cached SSL sessions in unrelated contexts, allowing virtual + host confusion attacks in some configurations. + This issue was assigned CVE-2014-3616. +
    + + A source code patch exists which remedies this problem. +

    +