No description
Find a file
Markus Koschany 6d83f8075c Import Debian changes 1.14.2-2+deb10u5
nginx (1.14.2-2+deb10u5) buster-security; urgency=high
.
  * Non-maintainer upload by the LTS team.
  * Fix CVE-2021-3618:
    ALPACA is an application layer protocol content confusion attack,
    exploiting TLS servers implementing different protocols but using
    compatible certificates, such as multi-domain or wildcard certificates. A
    MiTM attacker having access to victim's traffic at the TCP/IP layer can
    redirect traffic from one subdomain to another, resulting in a valid TLS
    session. This breaks the authentication of TLS and cross-protocol attacks
    may be possible where the behavior of one protocol service may compromise
    the other at the application layer.
  * Fix CVE-2022-41741 and CVE-2022-41742:
    It was discovered that parsing errors in the mp4 module of Nginx, a
    high-performance web and reverse proxy server, could result in denial of
    service, memory disclosure or potentially the execution of arbitrary code
    when processing a malformed mp4 file.
.
nginx (1.14.2-2+deb10u4) buster-security; urgency=medium
.
  * CVE-2021-23017 (Closes: #989095)
.
nginx (1.14.2-2+deb10u3) buster-security; urgency=high
.
  * Non-maintainer upload by the Security Team.
  * bugfix: prevented request smuggling in the ngx.location.capture API
    (CVE-2020-11724) (Closes: #964950)
.
nginx (1.14.2-2+deb10u2) buster; urgency=medium
.
  * Handle CVE-2019-20372, error page request smuggling
    (Closes: #948579)
2022-11-26 18:34:32 +01:00
auto New upstream version 1.13.11 2018-04-09 08:40:16 +03:00
conf New upstream version 1.13.6 2017-10-11 10:33:46 +03:00
contrib New upstream version 1.13.10 2018-03-21 16:14:30 +02:00
debian Import Debian changes 1.14.2-2+deb10u5 2022-11-26 18:34:32 +01:00
html Imported Upstream version 1.2.4 2012-09-29 21:46:46 +05:30
man Imported Upstream version 1.9.2 2015-06-17 11:21:32 +03:00
src New upstream version 1.14.2 2018-12-04 17:22:42 +02:00
CHANGES New upstream version 1.14.2 2018-12-04 17:22:42 +02:00
CHANGES.ru New upstream version 1.14.2 2018-12-04 17:22:42 +02:00
configure New upstream version 1.13.2 2017-06-28 11:05:50 +03:00
LICENSE New upstream version 1.13.9 2018-02-20 18:57:58 +02:00
README Imported Upstream version 1.2.0 2012-05-08 07:55:35 +02:00

Documentation is available at http://nginx.org