Git-Url: http://git.frugalware.org/gitweb/gitweb.cgi?p=frugalware-1.9.git;a=commitdiff;h=e037148987081e3522e15f1d560b94bccdd15df5
commit e037148987081e3522e15f1d560b94bccdd15df5 Author: kikadf <[email protected]> Date: Thu Sep 25 08:29:52 2014 +0200 nginx-1.4.1-2arcturus1-x86_64 * Fix CVE-2013-4547, CVE-2014-3616 diff --git a/source/network-extra/nginx/CVE-2013-4547.patch b/source/network-extra/nginx/CVE-2013-4547.patch new file mode 100644 index 0000000..5521b92 --- /dev/null +++ b/source/network-extra/nginx/CVE-2013-4547.patch @@ -0,0 +1,30 @@ +From: Christos Trochalakis <[email protected]> +Date: Wed, 20 Nov 2013 00:26:42 +0200 +Subject: Fix CVE-2013-4547 + +backport of changeset 5446:988c22615014 from the nginx repo. +http://hg.nginx.org/nginx/rev/988c22615014 +--- + src/http/ngx_http_parse.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/http/ngx_http_parse.c b/src/http/ngx_http_parse.c +index be750ed..bda0b0d 100644 +--- a/src/http/ngx_http_parse.c ++++ b/src/http/ngx_http_parse.c +@@ -614,6 +614,7 @@ ngx_http_parse_request_line(ngx_http_request_t *r, ngx_buf_t *b) + default: + r->space_in_uri = 1; + state = sw_check_uri; ++ p--; + break; + } + break; +@@ -667,6 +668,7 @@ ngx_http_parse_request_line(ngx_http_request_t *r, ngx_buf_t *b) + default: + r->space_in_uri = 1; + state = sw_uri; ++ p--; + break; + } + break; diff --git a/source/network-extra/nginx/CVE-2014-3616.patch b/source/network-extra/nginx/CVE-2014-3616.patch new file mode 100644 index 0000000..6395395 --- /dev/null +++ b/source/network-extra/nginx/CVE-2014-3616.patch @@ -0,0 +1,23 @@ +Subject: fix CVE-2014-3616, Reuse cached SSL sessions in unrelated contexts +Origin: http://mailman.nginx.org/pipermail/nginx-devel/2014-September/005948.html +--- a/src/event/ngx_event_openssl.c ++++ b/src/event/ngx_event_openssl.c +@@ -1498,14 +1498,16 @@ ngx_int_t + ngx_ssl_session_cache(ngx_ssl_t *ssl, ngx_str_t *sess_ctx, + ssize_t builtin_session_cache, ngx_shm_zone_t *shm_zone, time_t timeout) + { +- long cache_mode; ++ long cache_mode; ++ u_char buf[16]; + + if (builtin_session_cache == NGX_SSL_NO_SCACHE) { + SSL_CTX_set_session_cache_mode(ssl->ctx, SSL_SESS_CACHE_OFF); + return NGX_OK; + } + +- SSL_CTX_set_session_id_context(ssl->ctx, sess_ctx->data, sess_ctx->len); ++ RAND_pseudo_bytes(buf, 16); ++ SSL_CTX_set_session_id_context(ssl->ctx, buf, 16); + + if (builtin_session_cache == NGX_SSL_NONE_SCACHE) { + diff --git a/source/network-extra/nginx/FrugalBuild b/source/network-extra/nginx/FrugalBuild index 7dc890a..f422526 100644 --- a/source/network-extra/nginx/FrugalBuild +++ b/source/network-extra/nginx/FrugalBuild @@ -3,7 +3,7 @@ pkgname=nginx pkgver=1.4.1 -pkgrel=1 +pkgrel=2arcturus1 pkgdesc="[engine x] is a HTTP server and mail proxy server." url="http://nginx.net/" license="BSD" @@ -14,10 +14,20 @@ provides=('httpd') backup=(etc/$pkgname/$pkgname.conf) up2date="lynx -dump http://nginx.org/ |grep stable |sed -ne 's/.*nx-\(.*\) st.*/\1/;1p'" source=(http://nginx.org/download/nginx-$pkgver.tar.gz $pkgname.service $pkgname.logrotate) +sha1sums=('9c72838973572323535dae10f4e412d671b27a7e' \ + '5652c45190662cb2bf4ba261ce08728289b4fef8' \ + 'da58d8a74dbb081c3dfb69317999e10f1ebf991e') _F_systemd_units=($pkgname=) Finclude systemd + +# FSA fix *** +source=(${source[@]} CVE-2013-4547.patch CVE-2014-3616.patch) +sha1sums=(${sha1sums[@]} 'd13a89f4d625187254d9f886a4506b18b14d18ab' \ + '91e0d385928f22a20d9fa9f9af0cc62c908b4fba') +# *********** + build() { Fpatchall Fmake --prefix=$Fsysconfdir/$pkgname \ @@ -67,8 +77,9 @@ build() { Fgenscriptlet } -sha1sums=('9c72838973572323535dae10f4e412d671b27a7e' \ - '5652c45190662cb2bf4ba261ce08728289b4fef8' \ - 'da58d8a74dbb081c3dfb69317999e10f1ebf991e') + + + + # optimization OK _______________________________________________ Frugalware-git mailing list [email protected] http://frugalware.org/mailman/listinfo/frugalware-git
