bevor ich deswegen angerufen werde ;)... das teil ist eigtl nur fuer shared host o.ä. relevant (wo ich von nem anderen vhost was abgreifen will), und auch nur dann wenn man php hochladen und ausfuehren kann. und wenn das irgendwo bei uns ginge, hätte man eh zugriff auf alle vhosts auf dem server, inkl mysql configs, ergo auf alle sensitiven daten. ergo ist die luecke nicht relevant.
bis montag! veit On Mar 20, 2012 12:20 AM, "Luciano Bello" <[email protected]> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > - ------------------------------------------------------------------------- > Debian Security Advisory DSA-2434-1 [email protected] > http://www.debian.org/security/ Luciano Bello > March 19, 2012 http://www.debian.org/security/faq > - ------------------------------------------------------------------------- > > Package : nginx > Vulnerability : sensitive information leak > Problem type : remote > Debian-specific: no > CVE ID : CVE-2012-1180 > Debian Bug : 664137 > > Matthew Daley discovered a memory disclosure vulnerability in nginx. In > previous versions of this web server, an attacker can receive the content > of > previously freed memory if an upstream server returned a specially crafted > HTTP > response, potentially exposing sensitive information. > > For the stable distribution (squeeze), this problem has been fixed in > version 0.7.67-3+squeeze2. > > For the unstable distribution (sid), this problem has been fixed in > version 1.1.17-1. > > We recommend that you upgrade your nginx packages. > > Further information about Debian Security Advisories, how to apply > these updates to your system and frequently asked questions can be > found at: http://www.debian.org/security/ > > Mailing list: [email protected] > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.11 (GNU/Linux) > > iEYEARECAAYFAk9nuSsACgkQQWTRs4lLtHmBXgCfQ9bc7DxAo5RIKuPF8UgSaGxn > zXUAn3T+A7FpQ6iyr2Ebh2pIoBdPHVz2 > =3d9U > -----END PGP SIGNATURE----- > > > -- > To UNSUBSCRIBE, email to [email protected] > with a subject of "unsubscribe". Trouble? Contact > [email protected] > Archive: http://lists.debian.org/[email protected] > >

