MGASA-2013-0160
Dashboard / Vulnerabilities / MGASA-2013-0160
Summary: Updated nginx package fixes security vulnerability
Details: A security problem related to CVE-2013-2028 was identified, affecting some previous nginx versions if proxy_pass to untrusted upstream HTTP servers is used. The problem may lead to a denial of service or a disclosure of a worker process memory on a specially crafted response from an upstream proxied server (CVE-2013-2070).
References: https://advisories.mageia.org/MGASA-2013-0160.html, http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html, http://nginx.org/en/CHANGES-1.2, http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105950.html
Affected packages
Package
Name: nginx
Purl: pkg:rpm/mageia/nginx?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
