nginx – Múltiples Vulnerabilidades

Thursday, 17. September 2009

Para los que usamos nginx les recomiendo descargarlo nuevamente ya que trae algunos arreglos de índole críticos, acá pueden ver la lista de cambios la cual copie & pegue para los vagos.

    *) Security: a segmentation fault might occur in worker process while
       specially crafted request handling.
       Thanks to Chris Ries.

    *) Feature: the $upstream_cache_status variable.

    *) Bugfix: an expired cached response might stick in the "UPDATING"
       state.

    *) Bugfix: a segmentation fault might occur in worker process, if
       error_log was set to info or debug level.
       Thanks to Sergey Bochenkov.

    *) Bugfix: in handling FastCGI headers split in records.

    *) Bugfix: XSLT filter may fail with message "not well formed XML
       document" for valid XML document.
       Thanks to Kuramoto Eiji.

    *) Bugfix: now in MacOSX, Cygwin, and nginx/Windows locations given by
       a regular expression are always tested in case insensitive mode.

    *) Bugfix: now nginx/Windows ignores trailing dots in URI.
       Thanks to Hugo Leisink.

    *) Bugfix: name of file specified in --conf-path was not honored during
       installation; the bug had appeared in 0.6.6.
       Thanks to Maxim Dounin.

    *) Bugfix: a 500 error code was returned for invalid login/password
       while HTTP Basic authentication on Windows.

Las versiones afectadas son las inferiores a 0.7.62, 0.6.39, ó 0.5.38. Pueden descargar la nueva aquí.

Comments are closed.