TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Nginx security update

67 pointsby pyritschardalmost 12 years ago

6 comments

oinksoftalmost 12 years ago
Just a PSA for people running Debian servers: Subscribe to the debian-security-announce list[1] and you&#x27;ll get these notices in your inbox rather than at the top of Hacker News. I got an email Sunday afternoon so when I saw this I thought ... another vulnerability, already?!<p>[1] <a href="http://lists.debian.org/debian-security-announce/" rel="nofollow">http:&#x2F;&#x2F;lists.debian.org&#x2F;debian-security-announce&#x2F;</a>
评论 #6013852 未加载
ck2almost 12 years ago
Note that&#x27;s for Debian distribution.<p>Patched source was actually posted back on May 7th and 13th for people who compile their own builds.<p><pre><code> 2013-05-07 nginx-1.4.1 stable and nginx-1.5.0 development versions have been released, with the fix for the stack-based buffer overflow security problem in nginx 1.3.9 - 1.4.0, discovered by Greg MacManus, of iSIGHT Partners Labs (CVE-2013-2028). 2013-05-13 nginx-1.2.9 legacy version has been released, addressing the information disclosure security problem in some previous nginx versions (CVE-2013-2070).</code></pre>
评论 #6012890 未加载
评论 #6012489 未加载
danielpalalmost 12 years ago
The NGINX advisory is here: <a href="http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html" rel="nofollow">http:&#x2F;&#x2F;mailman.nginx.org&#x2F;pipermail&#x2F;nginx-announce&#x2F;2013&#x2F;00011...</a><p>This is almost 2 months old.
samwillisalmost 12 years ago
Am I right in interpreting this as only a vulnerability if you use Nginx to proxy to an untrusted server (i.e. not yours) where specially formatted responses can compromise your Nginx?<p>It would seem to me that this is a particularly rare use case of nginx?<p>I suppose shared web hosts and services like CloudFlare are the types of implementation that may be affected.
评论 #6012463 未加载
评论 #6012460 未加载
antiheroalmost 12 years ago
And, thankfully, all the current packages in Debian are either unaffected or it&#x27;s been patched :)
hgezimalmost 12 years ago
Anyone know of the Ubuntu packages that are safe here?
评论 #6013428 未加载