LWN.net Logo

nginx: information disclosure

Package(s):nginx CVE #(s):CVE-2012-1180
Created:March 20, 2012 Updated:April 5, 2012
Description: From the Debian advisory:

Matthew Daley discovered a memory disclosure vulnerability in nginx. In previous versions of this web server, an attacker can receive the content of previously freed memory if an upstream server returned a specially crafted HTTP response, potentially exposing sensitive information.

Alerts:
Debian DSA-2434-1 2012-03-19
Gentoo 201203-22 2012-03-28
Mandriva MDVSA-2012:043 2012-03-29
Fedora FEDORA-2012-3991 2012-03-31
Fedora FEDORA-2012-4006 2012-03-31
openSUSE openSUSE-SU-2012:0469-1 2012-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds