version 1.22, 2014/09/06 13:59:35 |
version 1.23, 2014/09/30 19:44:30 |
|
|
A source code patch exists which remedies this problem.</a> |
A source code patch exists which remedies this problem.</a> |
<p> |
<p> |
|
|
|
<li><a name="011_nginx"></a> |
|
<font color="#009000"><strong>011: SECURITY FIX: October 1, 2014</strong></font> |
|
<i>All architectures</i><br> |
|
nginx can reuse cached SSL sessions in unrelated contexts, allowing virtual |
|
host confusion attacks in some configurations. |
|
This issue was assigned CVE-2014-3616. |
|
<br> |
|
<a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.5/common/011_nginx.patch.sig"> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
|
|
</ul> |
</ul> |
|
|
</body> |
</body> |