| Summary: | nginx new security issue CVE-2012-1180 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, derekjenn, dmorganec, fundawang, guillomovitch, sysadmin-bugs, tmb |
| Version: | 1 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://seclists.org/bugtraq/2012/Mar/65 | ||
| Whiteboard: | |||
| Source RPM: | nginx-1.0.0-1.mga1.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2012-03-29 12:05:12 CEST
David Walser
2012-03-29 12:05:34 CEST
CC:
(none) =>
guillomovitch
David Walser
2012-03-29 12:05:47 CEST
CC:
(none) =>
fundawang
David Walser
2012-03-29 12:05:58 CEST
CC:
(none) =>
dmorganec nginx-1.0.0-1.1.mga submitted to updates_testing, with upstream patch applied. Status:
NEW =>
ASSIGNED Is this ready for QA? I think so. Unless you expect more than rebuilding with a patch, of course :) :o) Thanks Guillaume. Advisory ======================== Updated nginx package fixes security vulnerability: Specially crafted backend response could result in sensitive information leak (CVE-2012-1180). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1180 https://bugzilla.redhat.com/show_bug.cgi?id=803856 http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:043 ======================== Updated packages in core/updates_testing: ======================== nginx-1.0.0-1.1.mga1 from nginx-1.0.0-1.1.mga1.src.rpm Assignee:
bugsquad =>
qa-bugs /usr/share/nginx/html/index.html should have the two occurrences of Mandriva replaced by Mageia and the icon shown from http://www.mandriva.com/"><img src="poweredby.png" alt="[ Powered by Mandriva ]" should either be removed or replaced with a Mageia icon, but that won't hold the update. I'll let you decide if you want to fix it, or if you would like me to open a new bug report for that. No POC, so just testing that it works. Testing complete on i586 for the srpm nginx-1.0.0-1.1.mga1.src.rpm CC:
(none) =>
davidwhodgins Testing complete on x86_64 for nginx-1.0.0-1.1.mga1.src.rpm Tested basic server functionality. Update validated. Could sysadmin please push nginx-1.0.0-1.1.mga1.src.rpm from core/updates_testing to core/updates please. Advisory ------- Updated nginx package fixes security vulnerability: Specially crafted backend response could result in sensitive information leak (CVE-2012-1180). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1180 https://bugzilla.redhat.com/show_bug.cgi?id=803856 http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:043 Keywords:
(none) =>
validated_update Update pushed. Status:
ASSIGNED =>
RESOLVED |