[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
The Precise Pangolin has reached end of life, so this bug will not be fixed for that release ** Changed in: nginx (Ubuntu Precise) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Debian) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Debian) Status: Fix Released => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
saucy has seen the end of its life and is no longer receiving any updates. Marking the saucy task for this ticket as Won't Fix. ** Changed in: nginx (Ubuntu Saucy) Status: Confirmed = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nginx in Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
saucy has seen the end of its life and is no longer receiving any updates. Marking the saucy task for this ticket as Won't Fix. ** Changed in: nginx (Ubuntu Saucy) Status: Confirmed = Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Ubuntu Quantal) Status: Confirmed = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nginx in Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Ubuntu Quantal) Status: Confirmed = Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Ubuntu Raring) Status: Confirmed = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nginx in Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Ubuntu Raring) Status: Confirmed = Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
Importance changed to Low with the blessings of the security team. Marc Deslauriers (mdeslaur) on IRC stated that the CVE is getting a Low importance state in the tracker, so I have adjusted the importance on this bug accordingly. ** Changed in: nginx (Ubuntu Precise) Importance: Medium = Low ** Changed in: nginx (Ubuntu Quantal) Importance: Medium = Low ** Changed in: nginx (Ubuntu Raring) Importance: Medium = Low ** Changed in: nginx (Ubuntu Saucy) Importance: Medium = Low ** Changed in: nginx (Ubuntu Trusty) Importance: Medium = Low -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Debian) Status: New = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
1.4.4-2ubuntu1 was uploaded by cjwatson and was published on December 28, 2013 in Trusty. This merge of 1.4.4-2 from Debian Unstable contained the changes which closed Debian bug 701112 (which is linked to this bug). This fix is now in Trusty, however the changelog for 1.4.4-2ubuntu1 did not reference this bug number so it was not automatically Fix Released for Trusty. ** Changed in: nginx (Ubuntu Trusty) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
I know that at the very least, Precise, Quantal, Raring, Saucy, and Trusty are affected by this bug. I believe that Lucid may also be affected and I will have to look into that to confirm. I have asked Colin Watson (cjwatson) to merge 1.4.4-2 from Debian to Trusty, as 1.4.4-2 contains the fix for this, as well as other Debian bugfixes. I have the diff from Debian git (see http://anonscm.debian.org/gitweb/?p =collab- maint/nginx.git;a=commitdiff_plain;h=3a4f08671c87b7fc89e077542edfd6eb651f1803 for the diff) that applies a fix for this, and will nit-pick the specific changes from this for the security fixes for the affected Ubuntu versions. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Also affects: nginx (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: nginx (Ubuntu Quantal) Importance: Undecided Status: New ** Also affects: nginx (Ubuntu Raring) Importance: Undecided Status: New ** Also affects: nginx (Ubuntu Saucy) Importance: Undecided Status: New ** Also affects: nginx (Ubuntu Trusty) Importance: Medium Status: Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Ubuntu Precise) Status: New = Confirmed ** Changed in: nginx (Ubuntu Precise) Importance: Undecided = Medium ** Changed in: nginx (Ubuntu Quantal) Status: New = Confirmed ** Changed in: nginx (Ubuntu Raring) Status: New = Confirmed ** Changed in: nginx (Ubuntu Saucy) Status: New = Confirmed ** Changed in: nginx (Ubuntu Saucy) Importance: Undecided = Medium ** Changed in: nginx (Ubuntu Raring) Importance: Undecided = Medium ** Changed in: nginx (Ubuntu Quantal) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Description changed: This is CVE-2013-0337. After installing nginx, /var/log/nginx is world readable as reported in http://www.openwall.com/lists/oss-security/2013/02/21/15. (this description is lifted from the Debian bug) - This is reported in Debian as 701112. + This is reported in Debian as #701112. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1193445] Re: Directory /var/log/nginx is world readable [CVE-2013-0337]
** Changed in: nginx (Debian) Status: Unknown = New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1193445 Title: Directory /var/log/nginx is world readable [CVE-2013-0337] To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1193445/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs