mailing list archives
Re: CVE Request: nginx fix for malformed HTTP responses from upstream servers
From: Kurt Seifried <kseifried () redhat com>
Date: Thu, 15 Mar 2012 12:39:52 -0600
On 03/15/2012 07:37 AM, Andrew Alexeev wrote:
The nginx team has released stable version 1.0.14, and development
version 1.1.17 of nginx web server, which include a fix for malformed
HTTP responses from upstream servers:
Memory disclosure with specially crafted backend responses
Not vulnerable: 1.1.17+, 1.0.14+
The patch pgp
Without this fix contents of previously freed memory might be sent to
a client if an upstream server returned specially crafted response,
potentially resulting in sensitive information leak.
Patch which can be applied to the earlier versions of nginx is here:
Thanks to Matthew Daley for spotting this one.
This is a nicely formatted CVE request. In future if you want a CVE in
advance you can request one via the VS list and I'll be happy to assign
it privately there.
Please use CVE-2012-1180 for this issue.
Kurt Seifried Red Hat Security Response Team (SRT)