Back to list
nginx fix for malformed HTTP responses from upstream servers
Mar 15 2012 01:48PM
security-bulletin nginx com
The nginx team has released stable version 1.0.14, and development
version 1.1.17 of nginx web server, which include a fix for malformed
HTTP responses from upstream servers:
Without this fix contents of previously freed memory might be sent to
a client if an upstream server returned specially crafted response,
potentially resulting in sensitive information leak.
Patch which can be applied to the earlier versions of nginx is here:
Thanks to Matthew Daley for spotting this one.
-- nginx team
[ reply ]
Copyright 2010, SecurityFocus