3 ms·
Nginx security update
- samwillis 13y agoAm I right in interpreting this as only a vulnerability if you use Nginx to proxy to an untrusted server (i.e. not yours) where specially formatted responses can compromise your Nginx? It would seem to me that this is a particularly rare use case of nginx? I suppose shared web hosts and services like CloudFlare are the types of implementation that may be affected.
- byroot 13y agoYes, you interpret it correctly. It's not that common, but I know at least an app using nginx in that way, and it was performing very well.
- DrJokepu 13y agoYes but this can be exploited if a trusted backend server (which is much more common) gets compromised. Basically if you have nginx in front of Node and you manage to execute arbitrary code in Node you could use this as an attack vector to compromise nginx which could act as a front-end to a whole lot of other things.
- ck2 13y agoNote that's for Debian distribution. Patched source was actually posted back on May 7th and 13th for people who compile their own builds. 2013-05-07 nginx-1.4.1 stable and nginx-1.5.0 development versions have been released, with the fix for the stack-based buffer overflow security problem in nginx 1.3.9 - 1.4.0, discovered by Greg MacManus, of iSIGHT Partners Labs (CVE-2013-2028). 2013-05-13 nginx-1.2.9 legacy version has been released, addressing the information disclosure security problem in some previous nginx versions (CVE-2013-2070).
- GibbyBorn 13y agoWell, debian guys are so slow. It's the most unsecure and unstable distribution.
- antihero 13y agoWe've had the fixed versions of the packages for quite some time.
- philtar 13y agoWhat's the difference between wheezy and wheezy (security)? https://security-tracker.debian.org/tracker/CVE-2013-2070 https://security-tracker.debian.org/tracker/CVE-2013-2070
- antihero 13y agoWheezy is the base packages, security is security updates, which are enabled by default, and most sysadmins will enable automatic upgrading to.
- astrodust 13y agoSo is 1.4.1 okay?
- enduser 13y agoYes
- antihero 13y agoAnd, thankfully, all the current packages in Debian are either unaffected or it's been patched :)
- oinksoft 13y agoJust a PSA for people running Debian servers: Subscribe to the debian-security-announce list[1] and you'll get these notices in your inbox rather than at the top of Hacker News. I got an email Sunday afternoon so when I saw this I thought ... another vulnerability, already?! [1] http://lists.debian.org/debian-security-announce/ http://lists.debian.org/debian-security-announce/
- pallandt 13y agoNice tip, thanks!
- hgezim 13y agoAnyone know of the Ubuntu packages that are safe here?
- mclemme 13y agoSeems to be ok http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-2070.html http://people.canonical.com/~ubuntu-security/cve/2013/CVE-20...
- danielpal 13y agoThe NGINX advisory is here: http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html http://mailman.nginx.org/pipermail/nginx-announce/2013/00011... This is almost 2 months old.