nginx-sid/debian/modules
Markus Koschany 6d83f8075c Import Debian changes 1.14.2-2+deb10u5
nginx (1.14.2-2+deb10u5) buster-security; urgency=high
.
  * Non-maintainer upload by the LTS team.
  * Fix CVE-2021-3618:
    ALPACA is an application layer protocol content confusion attack,
    exploiting TLS servers implementing different protocols but using
    compatible certificates, such as multi-domain or wildcard certificates. A
    MiTM attacker having access to victim's traffic at the TCP/IP layer can
    redirect traffic from one subdomain to another, resulting in a valid TLS
    session. This breaks the authentication of TLS and cross-protocol attacks
    may be possible where the behavior of one protocol service may compromise
    the other at the application layer.
  * Fix CVE-2022-41741 and CVE-2022-41742:
    It was discovered that parsing errors in the mp4 module of Nginx, a
    high-performance web and reverse proxy server, could result in denial of
    service, memory disclosure or potentially the execution of arbitrary code
    when processing a malformed mp4 file.
.
nginx (1.14.2-2+deb10u4) buster-security; urgency=medium
.
  * CVE-2021-23017 (Closes: #989095)
.
nginx (1.14.2-2+deb10u3) buster-security; urgency=high
.
  * Non-maintainer upload by the Security Team.
  * bugfix: prevented request smuggling in the ngx.location.capture API
    (CVE-2020-11724) (Closes: #964950)
.
nginx (1.14.2-2+deb10u2) buster; urgency=medium
.
  * Handle CVE-2019-20372, error page request smuggling
    (Closes: #948579)
2022-11-26 18:34:32 +01:00
..
http-auth-pam mod: Normalize module locations 2017-10-12 10:37:22 +03:00
http-cache-purge mod: Normalize module locations 2017-10-12 10:37:22 +03:00
http-dav-ext http-dav-ext: Upgrade to 3.0.0 2018-12-27 12:46:53 +02:00
http-echo http-echo: Upgrade to 0.61 2017-12-14 11:03:38 +02:00
http-fancyindex http-fancyindex: Upgrade to 0.4.3 2018-08-31 15:15:27 +03:00
http-headers-more-filter http-headers-more-filter: Upgrade to 0.33 2017-12-14 11:03:38 +02:00
http-lua Import Debian changes 1.14.2-2+deb10u5 2022-11-26 18:34:32 +01:00
http-ndk mod: Normalize module locations 2017-10-12 10:37:22 +03:00
http-subs-filter mod: Normalize module locations 2017-10-12 10:37:22 +03:00
http-uploadprogress mod: Normalize module locations 2017-10-12 10:37:22 +03:00
http-upstream-fair mod: Normalize module locations 2017-10-12 10:37:22 +03:00
nchan Import Debian changes 1.14.2-2+deb10u5 2022-11-26 18:34:32 +01:00
patches Import Debian changes 1.14.2-2+deb10u5 2022-11-26 18:34:32 +01:00
rtmp rtmp: Upgrade to 1.2.1 2017-12-14 11:03:38 +02:00
watch Bits & pieces for ngxmod 2017-12-14 11:03:38 +02:00
control http-dav-ext: Upgrade to 3.0.0 2018-12-27 12:46:53 +02:00