Bug 26086 - nginx new security issue CVE-2019-20372
Summary: nginx new security issue CVE-2019-20372
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-01-15 23:11 CET by David Walser
Modified: 2020-05-27 11:53 CEST (History)
5 users (show)

See Also:
Source RPM: nginx-1.16.1-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-01-15 23:11:44 CET
Ubuntu has issued an advisory on January 13:
https://usn.ubuntu.com/4235-1/

The issue is fixed upstream in 1.17.7.
David Walser 2020-01-24 13:29:09 CET

Status comment: (none) => Patch available from Ubuntu

Comment 1 David Walser 2020-02-07 21:34:58 CET
SUSE has issued an advisory for this on February 6:
http://lists.suse.com/pipermail/sle-security-updates/2020-February/006462.html
Comment 2 Elliot L 2020-05-23 19:42:57 CEST
https://paste.debian.net/1148448/

CC: (none) => CheeseEBoi

Comment 3 Elliot L 2020-05-23 19:45:17 CEST
Here is a proposed diff, ignore the previous one without the patch... I accidentally hit <enter>.

https://paste.debian.net/1148450/
Comment 4 Elliot L 2020-05-23 19:58:16 CEST
Better proposed patch

https://paste.debian.net/1148455/
Comment 5 Elliot L 2020-05-23 20:07:56 CEST
Advisory:
========================
Nginx was updated due to the following vulnerabilities:

ngx_http_special_response.c: With a certain error_page configuration, HTTP request smuggling is possible. Thus, an attacker may be able to read unauthorized web pages at times when NGINX is being fronted by a load balancer. (CVE-2019-20372).


References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20372
https://usn.ubuntu.com/4235-1/

========================
Updated the package in core/updates_testing:

nginx-1.16.1-1.2.mga7
from nginx-1.16.1-1.2.mga7.src.rpm
David Walser 2020-05-23 20:09:14 CEST

Assignee: smelror => qa-bugs
Status comment: Patch available from Ubuntu => (none)

Comment 6 Herman Viaene 2020-05-24 15:13:56 CEST
MGA7-64 Plasma on Lenovo B50 
No installation issues
Followed procedure as per bug 13044:
# systemctl stop httpd
# nginx 
then point browser at http://localhost/ 
and get in  the page: "Welcome to nginx 1.6.1 on Mageia!"

OK for me.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 7 Thomas Andrews 2020-05-26 02:57:38 CEST
Validating. Advisory in Comment 5.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Nicolas Lécureuil 2020-05-27 11:07:23 CEST

CC: (none) => mageia
Keywords: (none) => advisory

Comment 8 Mageia Robot 2020-05-27 11:53:57 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0231.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.