nginx – Múltiples Vulnerabilidades

Para los que usamos nginx les recomiendo descargarlo nuevamente ya que trae algunos arreglos de índole críticos, acá pueden ver la lista de cambios la cual copie & pegue para los vagos.

    *) Security: a segmentation fault might occur in worker process while
       specially crafted request handling.
       Thanks to Chris Ries.

    *) Feature: the $upstream_cache_status variable.

    *) Bugfix: an expired cached response might stick in the "UPDATING"
       state.

    *) Bugfix: a segmentation fault might occur in worker process, if
       error_log was set to info or debug level.
       Thanks to Sergey Bochenkov.

    *) Bugfix: in handling FastCGI headers split in records.

    *) Bugfix: XSLT filter may fail with message "not well formed XML
       document" for valid XML document.
       Thanks to Kuramoto Eiji.

    *) Bugfix: now in MacOSX, Cygwin, and nginx/Windows locations given by
       a regular expression are always tested in case insensitive mode.

    *) Bugfix: now nginx/Windows ignores trailing dots in URI.
       Thanks to Hugo Leisink.

    *) Bugfix: name of file specified in --conf-path was not honored during
       installation; the bug had appeared in 0.6.6.
       Thanks to Maxim Dounin.

    *) Bugfix: a 500 error code was returned for invalid login/password
       while HTTP Basic authentication on Windows.

Las versiones afectadas son las inferiores a 0.7.62, 0.6.39, ó 0.5.38. Pueden descargar la nueva aquí.
Esta entrada fue publicada en /opt/blog/linux, /opt/blog/opensource, /opt/blog/security, /opt/blog/webservers. Guarda el enlace permanente.

Los comentarios están cerrados.