Home page logo

oss-sec logo oss-sec mailing list archives

CVE Request: nginx fix for malformed HTTP responses from upstream servers
From: Andrew Alexeev <andrew () nginx com>
Date: Thu, 15 Mar 2012 17:37:29 +0400


The nginx team has released stable version 1.0.14, and development
version 1.1.17 of nginx web server, which include a fix for malformed
HTTP responses from upstream servers:



Without this fix contents of previously freed memory might be sent to
a client if an upstream server returned specially crafted response,
potentially resulting in sensitive information leak.

Patch which can be applied to the earlier versions of nginx is here:

Thanks to Matthew Daley for spotting this one.

Andrew Alexeev

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]