TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Nginx security update

67 点作者 pyritschard将近 12 年前

6 条评论

oinksoft将近 12 年前
Just a PSA for people running Debian servers: Subscribe to the debian-security-announce list[1] and you&#x27;ll get these notices in your inbox rather than at the top of Hacker News. I got an email Sunday afternoon so when I saw this I thought ... another vulnerability, already?!<p>[1] <a href="http://lists.debian.org/debian-security-announce/" rel="nofollow">http:&#x2F;&#x2F;lists.debian.org&#x2F;debian-security-announce&#x2F;</a>
评论 #6013852 未加载
ck2将近 12 年前
Note that&#x27;s for Debian distribution.<p>Patched source was actually posted back on May 7th and 13th for people who compile their own builds.<p><pre><code> 2013-05-07 nginx-1.4.1 stable and nginx-1.5.0 development versions have been released, with the fix for the stack-based buffer overflow security problem in nginx 1.3.9 - 1.4.0, discovered by Greg MacManus, of iSIGHT Partners Labs (CVE-2013-2028). 2013-05-13 nginx-1.2.9 legacy version has been released, addressing the information disclosure security problem in some previous nginx versions (CVE-2013-2070).</code></pre>
评论 #6012890 未加载
评论 #6012489 未加载
danielpal将近 12 年前
The NGINX advisory is here: <a href="http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html" rel="nofollow">http:&#x2F;&#x2F;mailman.nginx.org&#x2F;pipermail&#x2F;nginx-announce&#x2F;2013&#x2F;00011...</a><p>This is almost 2 months old.
samwillis将近 12 年前
Am I right in interpreting this as only a vulnerability if you use Nginx to proxy to an untrusted server (i.e. not yours) where specially formatted responses can compromise your Nginx?<p>It would seem to me that this is a particularly rare use case of nginx?<p>I suppose shared web hosts and services like CloudFlare are the types of implementation that may be affected.
评论 #6012463 未加载
评论 #6012460 未加载
antihero将近 12 年前
And, thankfully, all the current packages in Debian are either unaffected or it&#x27;s been patched :)
hgezim将近 12 年前
Anyone know of the Ubuntu packages that are safe here?
评论 #6013428 未加载