[ubuntu/trusty-updates] nginx 1.4.6-1ubuntu3.4 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Tue Feb 9 18:28:12 UTC 2016
nginx (1.4.6-1ubuntu3.4) trusty-security; urgency=medium
* SECURITY UPDATE: multiple resolver security issues (LP: #1538165)
- debian/patches/CVE-2016-074x-1.patch: fix possible segmentation fault
on DNS format error.
- debian/patches/CVE-2016-074x-2.patch: fix crashes in timeout handler.
- debian/patches/CVE-2016-074x-3.patch: fixed CNAME processing for
several requests.
- debian/patches/CVE-2016-074x-4.patch: change the
ngx_resolver_create_*_query() arguments.
- debian/patches/CVE-2016-074x-5.patch: fix use-after-free memory
accesses with CNAME.
- debian/patches/CVE-2016-074x-6.patch: limited CNAME recursion.
- CVE-2016-0742
- CVE-2016-0743
- CVE-2016-0744
Date: 2016-02-03 16:22:14.144174+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.4
-------------- next part --------------
Sorry, changesfile not available.
More information about the Trusty-changes
mailing list