nginx: resolver CVEs: CVE-2016-0742 CVE-2016-0746 CVE-2016-0747

Related Vulnerabilities: CVE-2016-0742   CVE-2016-0746   CVE-2016-0747   CVE-2014-3616  

Debian Bug report logs - #812806
nginx: resolver CVEs: CVE-2016-0742 CVE-2016-0746 CVE-2016-0747

version graph

Reported by: Christos Trochalakis <yatiohi@ideopolis.gr>

Date: Tue, 26 Jan 2016 18:03:01 UTC

Severity: important

Tags: security, upstream

Found in versions nginx/0.7.67-1, nginx/1.9.9-1

Fixed in versions nginx/1.9.10-1, nginx/0.7.67-3+squeeze4+deb6u1, nginx/1.2.1-2.2+wheezy4

Done: Christos Trochalakis <yatiohi@ideopolis.gr>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Kartik Mistry <kartik@debian.org>:
Bug#812806; Package src:nginx. (Tue, 26 Jan 2016 18:03:05 GMT) (full text, mbox, link).


Acknowledgement sent to Christos Trochalakis <yatiohi@ideopolis.gr>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Kartik Mistry <kartik@debian.org>. (Tue, 26 Jan 2016 18:03:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Christos Trochalakis <yatiohi@ideopolis.gr>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: nginx: resolver CVEs: CVE-2016-0742 CVE-2016-0746 CVE-2016-0747
Date: Tue, 26 Jan 2016 19:58:03 +0200
Source: nginx
Severity: important
Tags: security upstream

Several problems in nginx resolver were identified, which might
allow an attacker to cause worker process crash, or might have
potential other impact:

- Invalid pointer dereference might occur during DNS server response
 processing, allowing an attacker who is able to forge UDP
 packets from the DNS server to cause worker process crash
 (CVE-2016-0742).

- Use-after-free condition might occur during CNAME response
 processing.  This problem allows an attacker who is able to trigger
 name resolution to cause worker process crash, or might
 have potential other impact (CVE-2016-0746).

- CNAME resolution was insufficiently limited, allowing an attacker who
 is able to trigger arbitrary name resolution to cause excessive resource
 consumption in worker processes (CVE-2016-0747).

The problems affect nginx 0.6.18 - 1.9.9 if the "resolver" directive
is used in a configuration file.

The problems are fixed in nginx 1.9.10, 1.8.1.
http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html




Reply sent to Christos Trochalakis <yatiohi@ideopolis.gr>:
You have taken responsibility. (Tue, 26 Jan 2016 18:36:14 GMT) (full text, mbox, link).


Notification sent to Christos Trochalakis <yatiohi@ideopolis.gr>:
Bug acknowledged by developer. (Tue, 26 Jan 2016 18:36:14 GMT) (full text, mbox, link).


Message #10 received at 812806-close@bugs.debian.org (full text, mbox, reply):

From: Christos Trochalakis <yatiohi@ideopolis.gr>
To: 812806-close@bugs.debian.org
Subject: Bug#812806: fixed in nginx 1.9.10-1
Date: Tue, 26 Jan 2016 18:34:26 +0000
Source: nginx
Source-Version: 1.9.10-1

We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 812806@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christos Trochalakis <yatiohi@ideopolis.gr> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Tue, 26 Jan 2016 20:12:06 +0200
Source: nginx
Binary: nginx nginx-doc nginx-common nginx-full nginx-full-dbg nginx-light nginx-light-dbg nginx-extras nginx-extras-dbg
Architecture: source all amd64
Version: 1.9.10-1
Distribution: unstable
Urgency: medium
Maintainer: Kartik Mistry <kartik@debian.org>
Changed-By: Christos Trochalakis <yatiohi@ideopolis.gr>
Description:
 nginx      - small, powerful, scalable web/proxy server
 nginx-common - small, powerful, scalable web/proxy server - common files
 nginx-doc  - small, powerful, scalable web/proxy server - documentation
 nginx-extras - nginx web/proxy server (extended version)
 nginx-extras-dbg - nginx web/proxy server (extended version) - debugging symbols
 nginx-full - nginx web/proxy server (standard version)
 nginx-full-dbg - nginx web/proxy server (standard version) - debugging symbols
 nginx-light - nginx web/proxy server (basic version)
 nginx-light-dbg - nginx web/proxy server (basic version) - debugging symbols
Closes: 808699 812806
Changes:
 nginx (1.9.10-1) unstable; urgency=medium
 .
   [ Christos Trochalakis ]
   * New upstream release (1.9.10) (Closes: #812806)
   * debian/control:
     + Drop python dependency from nginx-common. (Closes: #808699)
Checksums-Sha1:
 5ce4fe4f1b6149c73855e4fbb4b137d5213bd138 2814 nginx_1.9.10-1.dsc
 b7ddb8bb55ad20c336c94526cd2c26b5699caeb5 889267 nginx_1.9.10.orig.tar.gz
 f5a401148daa1a594a8512475abbe9a1d9665e96 644936 nginx_1.9.10-1.debian.tar.xz
 5b9cdd9b4c02ffd932f58dcd04e842c465b7619d 97954 nginx-common_1.9.10-1_all.deb
 c26c474d15f1482228ccf73d1d0379e8c68f9b2e 89260 nginx-doc_1.9.10-1_all.deb
 276eb6e9e35bfcc0084cfc9b282a233f2ad0508d 5861022 nginx-extras-dbg_1.9.10-1_amd64.deb
 ad349d1c7391c73061b46dec8bc5023b6d239cbb 688818 nginx-extras_1.9.10-1_amd64.deb
 ff0688ed0e184e91301a2e53b39ddabd4c07959d 3786130 nginx-full-dbg_1.9.10-1_amd64.deb
 81cdc1a79088d5fcb6ff68efcad51530fd6a530c 498614 nginx-full_1.9.10-1_amd64.deb
 bd737a95d16a25decc0395f8e57f09a53b861835 2426290 nginx-light-dbg_1.9.10-1_amd64.deb
 1aaef49af0df13f3333c22bea9c6208eef8eee3c 367066 nginx-light_1.9.10-1_amd64.deb
 3120af8510f8de0e6e10a9f03a30c755cb29be7f 77766 nginx_1.9.10-1_all.deb
Checksums-Sha256:
 c340d3f52b7be21db0271b48327456fcfee15b5a56cfd453f28eb90950a09fdf 2814 nginx_1.9.10-1.dsc
 fb14d76844cab0a5a0880768be28965e74f9956790f618c454ef6098e26631d9 889267 nginx_1.9.10.orig.tar.gz
 fe5cc75d2861191a6ab39faf252de52d9d6385612dc55a2765b12d6ecaabaf42 644936 nginx_1.9.10-1.debian.tar.xz
 49f9e80bff09edfebd36121349efc7f07894c28d97fe620dfbea93fe865dde9a 97954 nginx-common_1.9.10-1_all.deb
 a4c1c70106762fa7c8b0f29b1730a3fd46a0fedfdf519ef5672409679cc23028 89260 nginx-doc_1.9.10-1_all.deb
 0b62722832b81a971cac0da808196ab14fd11ae47beb9f3e9e3127e06f688514 5861022 nginx-extras-dbg_1.9.10-1_amd64.deb
 d362bf46165f9f1abbb4cd67d8c84fdba8b3f0f9dbe877e115e76541b7439bc0 688818 nginx-extras_1.9.10-1_amd64.deb
 e8325faf44d5be4b2639fd131847fdfd91756c931edd4a21135f4a235a52a58f 3786130 nginx-full-dbg_1.9.10-1_amd64.deb
 38abe33aee63f84dfe0301226ae777ad7390d7442121e32fc38525290a71c755 498614 nginx-full_1.9.10-1_amd64.deb
 d4e829b07abbdf99c4c47211d280c1c85fbb335c99a2cc86ae2c2bbc65f1f6ee 2426290 nginx-light-dbg_1.9.10-1_amd64.deb
 5da06d95e7b1e53ba462be92a6be7a0625f2c1bd54191f60cfecfbac35918f04 367066 nginx-light_1.9.10-1_amd64.deb
 3a6c4ea7634d5569b6697fc2feac35209f9f743c4e034bdffe5f1908a6ded99a 77766 nginx_1.9.10-1_all.deb
Files:
 e0e47351d090b21511a1e5db6ddbd1dd 2814 httpd optional nginx_1.9.10-1.dsc
 64cc970988356a5e0fc4fcd1ab84fe57 889267 httpd optional nginx_1.9.10.orig.tar.gz
 8bca294325678702db2c2d248800a29a 644936 httpd optional nginx_1.9.10-1.debian.tar.xz
 4e2cea2ebedccf452bd360f182e21834 97954 httpd optional nginx-common_1.9.10-1_all.deb
 3c41519d83f0e7b79d101ca3d06ffb57 89260 doc optional nginx-doc_1.9.10-1_all.deb
 a660cdeef7bbe9ef8d30abf7a43b0da6 5861022 debug extra nginx-extras-dbg_1.9.10-1_amd64.deb
 e5b95d2824dc47aaf3785c67d4c4d69b 688818 httpd extra nginx-extras_1.9.10-1_amd64.deb
 539e520b1ff1100f832a9da0d5ffad6c 3786130 debug extra nginx-full-dbg_1.9.10-1_amd64.deb
 3a0e5893e824638aa1b00a050a7775bd 498614 httpd optional nginx-full_1.9.10-1_amd64.deb
 864a6b46ed32d69273101be98e817d32 2426290 debug extra nginx-light-dbg_1.9.10-1_amd64.deb
 3f71ba648ceb173a8d6164b7e5b78fad 367066 httpd extra nginx-light_1.9.10-1_amd64.deb
 52b5dd9e7c21dc848c6089f6ba503dcc 77766 httpd optional nginx_1.9.10-1_all.deb

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJWp7iMAAoJEBE2JgCnR+zZjSYP/3w2smwi7jEc58u/1DinZ0wI
tWW4lvfQZPFVPdMm6ikFBcLcjqjIlK2/wqXnhl7ew8Y2CdTYZyd6BxBPa/PpWH/d
i33rg52i5qEfB7AfX6aDxYUORbLgKKN1p93x2O0dMFOhfHvF4z/TrH373kiChOTS
aYAumwb1Uqe2vMuaeQabvKAwrcKwNrgnKqbc1t7ev0uJMInFJrquMfoSykdhodOb
ZY43s4LX+B3f/M/Ben2cqisiHpYcbTsuOY0T3cIm+bX+zGZdC3aD7uaI/Lsy9qYb
mc8jxsf0PbMf93WaAMwkttEJ24FacpsP52fOECbPbMJ1gYDHsTszR1P8dXzidivW
tJ0rF6rHBz9xrpmb4Xi1RyQASU9OBtLdIr68mk6SDCz4Ptjy/WlD4Z0R2wkpWuCP
SsP8IW5UMdrkDzyDgrrAFAyd7i8bmQaJthumLzWWVmI8R4Nzu9XzS3qH+CCuO4Cg
InTuQB2w2ueW9Pby+wAO5dVaOVMfwlkJ2+j51VX6fDXRcWvpXz4TfJtUlPnor0yf
4C2K9qWAtXuLvARDqbCaYVTG1jHflaFF4wg5CV6TXAROla5PQj4xKSXkl30R9zOT
hac3s5D9pAChscxcqhUWXYycHCcsEDfhUJ/U56I1XPF/DoKW5Y8K8pq7j8LlA2Kv
fK8MeyRuqwc+hr/7YSF3
=OBTS
-----END PGP SIGNATURE-----




Marked as found in versions nginx/1.9.9-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 26 Jan 2016 19:03:26 GMT) (full text, mbox, link).


Marked as found in versions nginx/0.7.67-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 26 Jan 2016 19:03:31 GMT) (full text, mbox, link).


Added tag(s) pending. Request was from Christos Trochalakis <yatiohi@ideopolis.gr> to control@bugs.debian.org. (Tue, 26 Jan 2016 19:03:35 GMT) (full text, mbox, link).


Message sent on to Christos Trochalakis <yatiohi@ideopolis.gr>:
Bug#812806. (Tue, 26 Jan 2016 19:04:02 GMT) (full text, mbox, link).


Message #19 received at 812806-submitter@bugs.debian.org (full text, mbox, reply):

From: Christos Trochalakis <yatiohi@ideopolis.gr>
To: 812806-submitter@bugs.debian.org
Subject: Bug#812806 marked as pending
Date: Tue, 26 Jan 2016 18:43:36 +0000
tag 812806 pending
thanks

Hello,

Bug #812806 reported by you has been fixed in the Git repository. You can
see the changelog below, and you can check the diff of the fix at:

    http://git.debian.org/?p=collab-maint/nginx.git;a=commitdiff;h=e752ea8

---
commit e752ea86a642040d3628dbfc496003403d1429bf
Author: Christos Trochalakis <yatiohi@ideopolis.gr>
Date:   Tue Jan 26 19:43:53 2016 +0200

    New upstream release (1.9.10)

diff --git a/debian/changelog b/debian/changelog
index 5e94be3..14d5de7 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,10 @@
+nginx (1.9.10-1) UNRELEASED; urgency=medium
+
+  [ Christos Trochalakis ]
+  * New upstream release (1.9.10) (Closes: #812806)
+
+ -- Christos Trochalakis <yatiohi@ideopolis.gr>  Tue, 26 Jan 2016 19:43:29 +0200
+
 nginx (1.9.9-1) unstable; urgency=medium
 
   [ Michael Lustfield ]



Reply sent to Chris Lamb <lamby@debian.org>:
You have taken responsibility. (Wed, 27 Jan 2016 10:27:13 GMT) (full text, mbox, link).


Notification sent to Christos Trochalakis <yatiohi@ideopolis.gr>:
Bug acknowledged by developer. (Wed, 27 Jan 2016 10:27:13 GMT) (full text, mbox, link).


Message #24 received at 812806-close@bugs.debian.org (full text, mbox, reply):

From: Chris Lamb <lamby@debian.org>
To: 812806-close@bugs.debian.org
Subject: Bug#812806: fixed in nginx 0.7.67-3+squeeze4+deb6u1
Date: Wed, 27 Jan 2016 10:26:31 +0000
Source: nginx
Source-Version: 0.7.67-3+squeeze4+deb6u1

We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 812806@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Chris Lamb <lamby@debian.org> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 27 Jan 2016 09:58:15 +0100
Source: nginx
Binary: nginx nginx-dbg
Architecture: source amd64
Version: 0.7.67-3+squeeze4+deb6u1
Distribution: squeeze-lts
Urgency: high
Maintainer: Jose Parrella <bureado@debian.org>
Changed-By: Chris Lamb <lamby@debian.org>
Description: 
 nginx      - small, but very powerful and efficient web server and mail proxy
 nginx-dbg  - Debugging symbols for nginx
Closes: 812806
Changes: 
 nginx (0.7.67-3+squeeze4+deb6u1) squeeze-lts; urgency=high
 .
   * CVE-2016-0742: Invalid pointer dereference might occur during DNS server
     response processing, allowing an attacker who is able to forge UDP packets
     from the DNS server to cause worker process crash. (Closes: #812806)
Checksums-Sha1: 
 67df99ec896831691ab60eb16df902ab2d390b4a 2048 nginx_0.7.67-3+squeeze4+deb6u1.dsc
 511a7c4b9f4296119e64eba54bd4ce241579e8bd 608462 nginx_0.7.67.orig.tar.gz
 92911db8cec9bfff90ffb1891007c77d10695dac 29229 nginx_0.7.67-3+squeeze4+deb6u1.debian.tar.gz
 937933011f7ae5fb555600e28f5d246bcb8f171f 357122 nginx_0.7.67-3+squeeze4+deb6u1_amd64.deb
 75db70a107d33b656a4b1547ec895421f849c85e 1967690 nginx-dbg_0.7.67-3+squeeze4+deb6u1_amd64.deb
Checksums-Sha256: 
 f7bdd24185ce0e3e0981ff44a1896d0752f010f4c8a94f9f11a402a74528a816 2048 nginx_0.7.67-3+squeeze4+deb6u1.dsc
 396c95055d041950831a9ee8ff54473436f212cd770c6bad0aa795637007f747 608462 nginx_0.7.67.orig.tar.gz
 fbf13bb1996ec232b1abc29f5d8797c11e4bb9e6c399a356c2bc9f06766aac77 29229 nginx_0.7.67-3+squeeze4+deb6u1.debian.tar.gz
 ef58eac64deb842a05e29a45bf77a9e7611b13d2a55503c4e08ea3b2331b6031 357122 nginx_0.7.67-3+squeeze4+deb6u1_amd64.deb
 9e9f603e8e7006b53544430820b8eeac4f4f14a25a1fe0fd7011b742aed5b54b 1967690 nginx-dbg_0.7.67-3+squeeze4+deb6u1_amd64.deb
Files: 
 961ea6c9626bdb97419a0d48615356c0 2048 httpd optional nginx_0.7.67-3+squeeze4+deb6u1.dsc
 b6e175f969d03a4d3c5643aaabc6a5ff 608462 httpd optional nginx_0.7.67.orig.tar.gz
 bef5b06689dc6ce1af38ada360d3d27b 29229 httpd optional nginx_0.7.67-3+squeeze4+deb6u1.debian.tar.gz
 1caade74ba02972f65d2af90747ccea1 357122 httpd optional nginx_0.7.67-3+squeeze4+deb6u1_amd64.deb
 9aeb77a81e1273c9a47d95eade3dfd4d 1967690 debug extra nginx-dbg_0.7.67-3+squeeze4+deb6u1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJWqI8nAAoJEB6VPifUMR5Y45wP/RyKj7JmG1arfKwtp+fVAxYl
GuZYQt8j6I1t8t298vNxzNj5QJzh0ObjD8uHs1WKrMtDZdiG0uGS2f3tLtq7+VQh
x/69uSE/uujoA8NG6EmEi9aIDZuEii5VaFHNZ1IcPMJ9lW2fcxdfn5kEKUbvZSJI
7M1RJ+odYZn3WypN6NQGbBiGxp/xvLehUBUqnqs3zA+Sur+3f18fZ4AXeO1D/ghb
qzK8GmrsSH9fkg+ZZEzr6+BjVDREKb1IpdbClq0k6F0WFF9kma0hMm+z2GfPScSB
COuDmji/DJdirmYxD3qKsyN0BSZE+ZiaPW9qXiABZw9RpDaqSu3POm3OWxMLSmY9
YKhX/CtDsdm+na7hbAg0MsEphtEs77Mdl0oR+ds/UyXA/dD3UnSHv3J+bEzbmgoe
16QzpHRRI6UxuNciWwvQAulz6xESL3K1OBG/PhEUS14ZArZ2JaDw5qAzpUFLsg/r
P4eEKfNJXBP++/gPW4JQSQwRZA/c1sqVKdBv3zbPyMlDvkF2dXDcu1ZCEKG0nMkM
3BS5bVhq9Z6e76pt2tQoq8Oxep+3YZjouHfuF+vxlIuxwgSxjtaHzRL4qmbfZ1qA
gzjMqWuXZnwVdIvfO9C9hbogih48Vq33RByk2Qy05u3CNsIRSBjBQsKADzgDmauU
2Xg8BLbCIaVcwH5kmQtR
=RZ7a
-----END PGP SIGNATURE-----




Added tag(s) pending. Request was from Christos Trochalakis <yatiohi@ideopolis.gr> to control@bugs.debian.org. (Fri, 12 Feb 2016 10:21:14 GMT) (full text, mbox, link).


Message sent on to Christos Trochalakis <yatiohi@ideopolis.gr>:
Bug#812806. (Fri, 12 Feb 2016 10:21:18 GMT) (full text, mbox, link).


Message #29 received at 812806-submitter@bugs.debian.org (full text, mbox, reply):

From: Christos Trochalakis <yatiohi@ideopolis.gr>
To: 812806-submitter@bugs.debian.org
Subject: Bug#812806 marked as pending
Date: Fri, 12 Feb 2016 10:16:38 +0000
tag 812806 pending
thanks

Hello,

Bug #812806 reported by you has been fixed in the Git repository. You can
see the changelog below, and you can check the diff of the fix at:

    http://git.debian.org/?p=collab-maint/nginx.git;a=commitdiff;h=1f3d6f6

---
commit 1f3d6f63ef8e2d84db79dde122e47be6e7af9cb5
Author: Christos Trochalakis <yatiohi@ideopolis.gr>
Date:   Thu Jan 28 13:44:01 2016 +0200

    Release 1.2.1-2.2+wheezy4

diff --git a/debian/changelog b/debian/changelog
index 8f8eb4c..2c76c12 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,12 @@
+nginx (1.2.1-2.2+wheezy4) wheezy-security; urgency=high
+
+  [ Christos Trochalakis ]
+  * Fixes multiple resolver CVEs,
+    CVE-2016-0742, CVE-2016-0746, CVE-2016-0747
+    Closes: #812806
+
+ -- Christos Trochalakis <yatiohi@ideopolis.gr>  Thu, 28 Jan 2016 13:42:29 +0200
+
 nginx (1.2.1-2.2+wheezy3) wheezy-security; urgency=high
 
   * debian/patches/fix-CVE-2014-3616.patch:



Reply sent to Christos Trochalakis <yatiohi@ideopolis.gr>:
You have taken responsibility. (Sat, 13 Feb 2016 21:51:10 GMT) (full text, mbox, link).


Notification sent to Christos Trochalakis <yatiohi@ideopolis.gr>:
Bug acknowledged by developer. (Sat, 13 Feb 2016 21:51:10 GMT) (full text, mbox, link).


Message #34 received at 812806-close@bugs.debian.org (full text, mbox, reply):

From: Christos Trochalakis <yatiohi@ideopolis.gr>
To: 812806-close@bugs.debian.org
Subject: Bug#812806: fixed in nginx 1.2.1-2.2+wheezy4
Date: Sat, 13 Feb 2016 21:47:46 +0000
Source: nginx
Source-Version: 1.2.1-2.2+wheezy4

We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 812806@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christos Trochalakis <yatiohi@ideopolis.gr> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 28 Jan 2016 13:42:29 +0200
Source: nginx
Binary: nginx nginx-doc nginx-common nginx-full nginx-full-dbg nginx-light nginx-light-dbg nginx-extras nginx-extras-dbg nginx-naxsi nginx-naxsi-dbg nginx-naxsi-ui
Architecture: source all amd64
Version: 1.2.1-2.2+wheezy4
Distribution: wheezy-security
Urgency: high
Maintainer: Kartik Mistry <kartik@debian.org>
Changed-By: Christos Trochalakis <yatiohi@ideopolis.gr>
Description: 
 nginx      - small, powerful, scalable web/proxy server
 nginx-common - small, powerful, scalable web/proxy server - common files
 nginx-doc  - small, powerful, scalable web/proxy server - documentation
 nginx-extras - nginx web/proxy server (extended version)
 nginx-extras-dbg - nginx web/proxy server (extended version) - debugging symbols
 nginx-full - nginx web/proxy server (standard version)
 nginx-full-dbg - nginx web/proxy server (standard version) - debugging symbols
 nginx-light - nginx web/proxy server (basic version)
 nginx-light-dbg - nginx web/proxy server (basic version) - debugging symbols
 nginx-naxsi - nginx web/proxy server (version with naxsi)
 nginx-naxsi-dbg - nginx web/proxy server (version with naxsi) - debugging symbols
 nginx-naxsi-ui - nginx web/proxy server - naxsi configuration front-end
Closes: 812806
Changes: 
 nginx (1.2.1-2.2+wheezy4) wheezy-security; urgency=high
 .
   [ Christos Trochalakis ]
   * Fixes multiple resolver CVEs,
     CVE-2016-0742, CVE-2016-0746, CVE-2016-0747
     Closes: #812806
Checksums-Sha1: 
 2d9db1d3b2dca648c0e6306522cd400ecfbfd97c 2800 nginx_1.2.1-2.2+wheezy4.dsc
 b4680d7917dc62b8a9664b088c129fbb6ec86fbb 1362828 nginx_1.2.1-2.2+wheezy4.debian.tar.gz
 bcc7a3c46b6250d1d62f3288de9db881cdf9ffba 61416 nginx_1.2.1-2.2+wheezy4_all.deb
 ba7d85d250c70d49844d7870c10cf0bd72658470 74254 nginx-doc_1.2.1-2.2+wheezy4_all.deb
 de67e437c4896f88750606113256a2f6cae68555 72824 nginx-common_1.2.1-2.2+wheezy4_all.deb
 04d39120cdc4f81eb210c90062859899cf4bbc5a 343276 nginx-naxsi-ui_1.2.1-2.2+wheezy4_all.deb
 affee58dec777f4c61a4ee87adc0b6afb024a626 435784 nginx-full_1.2.1-2.2+wheezy4_amd64.deb
 036d5041f9e9683f2359bea05b8c08285ecab3c4 3090350 nginx-full-dbg_1.2.1-2.2+wheezy4_amd64.deb
 ecf1e499fa517a51cf56527e08e1fa20fe852723 319546 nginx-light_1.2.1-2.2+wheezy4_amd64.deb
 76861fcbc84acb533115df7b53576e9d79357b2e 2134642 nginx-light-dbg_1.2.1-2.2+wheezy4_amd64.deb
 eeb8eaf02794c9d803df31d94432f56d0a3e0bb9 601798 nginx-extras_1.2.1-2.2+wheezy4_amd64.deb
 5fe8125d52e4eef24a7a17c3633de38a797958c2 4576854 nginx-extras-dbg_1.2.1-2.2+wheezy4_amd64.deb
 91f47f45636dc670fa0d8538c79b67033c7a1bd4 359102 nginx-naxsi_1.2.1-2.2+wheezy4_amd64.deb
 e47a955e560e13fcbd94aba7f30d8fd0e8fc3e86 2265698 nginx-naxsi-dbg_1.2.1-2.2+wheezy4_amd64.deb
Checksums-Sha256: 
 a4ca37d2831e90d93031384481caa6a3e3e4fe28e2240ab0776502c7e5afcc00 2800 nginx_1.2.1-2.2+wheezy4.dsc
 205f922a7ee57cab09c73875e14f5eb8029b82e92c5ac0fe2e49e2a26faff458 1362828 nginx_1.2.1-2.2+wheezy4.debian.tar.gz
 4a819e4f0fe3a4f621349fa140521ae5c6a65ef2a285615faea8ed8a60ad7dc6 61416 nginx_1.2.1-2.2+wheezy4_all.deb
 c4b2059d3974b8c4f3a6b823ec15342e506911e6e0712924a1a2330fed5262ec 74254 nginx-doc_1.2.1-2.2+wheezy4_all.deb
 5dec82be5034dced3d4567cfc485e8453480b30d718af8b0b50e4a392772121f 72824 nginx-common_1.2.1-2.2+wheezy4_all.deb
 85a85d3acfb38fcb2c50422a8a20ecb5cfd75aa1096154b9ebb9c8f470a0f255 343276 nginx-naxsi-ui_1.2.1-2.2+wheezy4_all.deb
 e07d98beeb651a73e4e052d3c322137926bd8b3c3cf5548b84bbbd2acf217caf 435784 nginx-full_1.2.1-2.2+wheezy4_amd64.deb
 8230882f2702abde501a892126bd5ae8e5556bdff7219c011e9f816732453dd1 3090350 nginx-full-dbg_1.2.1-2.2+wheezy4_amd64.deb
 e609b926ac24f2317d7987dc86fafa6a036428d2d4da9b164ba791e90f43a1c6 319546 nginx-light_1.2.1-2.2+wheezy4_amd64.deb
 1cfc582ef9045cbb5b3e7dbaf3c8db7db4214b7d626a2a709dae0dfb1f7ba129 2134642 nginx-light-dbg_1.2.1-2.2+wheezy4_amd64.deb
 afd1b6a41319d11c2e990653e8128a374e9330056a86a0e3c57db156b981e157 601798 nginx-extras_1.2.1-2.2+wheezy4_amd64.deb
 b7230f566d59cc2608ed3f35af1cf05a86b74c842172437ef5143648002a90f3 4576854 nginx-extras-dbg_1.2.1-2.2+wheezy4_amd64.deb
 0126f8e43cd5146d5697e35d85944a3f8face67bb1b7f721dfbfdb2bafd899d8 359102 nginx-naxsi_1.2.1-2.2+wheezy4_amd64.deb
 b16bce3e30aa61c603e1faa1f80f8831e878ebc731b2392923f7f837eccc9ee6 2265698 nginx-naxsi-dbg_1.2.1-2.2+wheezy4_amd64.deb
Files: 
 3b2d94c272f90fd90289bdfc4bfd4dd6 2800 httpd optional nginx_1.2.1-2.2+wheezy4.dsc
 5ca79ee79a2c65a40870ebc93a3fafe6 1362828 httpd optional nginx_1.2.1-2.2+wheezy4.debian.tar.gz
 ba533601ef76597f22a1c21ed943de15 61416 httpd optional nginx_1.2.1-2.2+wheezy4_all.deb
 a16b0d1bf9a58e34855bbf27c48f708a 74254 doc optional nginx-doc_1.2.1-2.2+wheezy4_all.deb
 84adb50343dc8508ee195cec2623ccb2 72824 httpd optional nginx-common_1.2.1-2.2+wheezy4_all.deb
 f9c9e23521f73c0a49be24c40eabfa86 343276 httpd extra nginx-naxsi-ui_1.2.1-2.2+wheezy4_all.deb
 2541e5c5ca697c1dd6e67f95c7a612fb 435784 httpd optional nginx-full_1.2.1-2.2+wheezy4_amd64.deb
 7afbc1b85901fa61c008bdc98b970aa3 3090350 debug extra nginx-full-dbg_1.2.1-2.2+wheezy4_amd64.deb
 7667a4d6ef9b8b64e1242798d06edc5e 319546 httpd extra nginx-light_1.2.1-2.2+wheezy4_amd64.deb
 065c8ca62cbf1a81edd631ecb70500c7 2134642 debug extra nginx-light-dbg_1.2.1-2.2+wheezy4_amd64.deb
 9af4600e8b4c35c68bd4d72a3f4ace5e 601798 httpd extra nginx-extras_1.2.1-2.2+wheezy4_amd64.deb
 7155598a0245bc6b97ad409ce13c4397 4576854 debug extra nginx-extras-dbg_1.2.1-2.2+wheezy4_amd64.deb
 64a223d394126ddffdabe70abd8918b3 359102 httpd extra nginx-naxsi_1.2.1-2.2+wheezy4_amd64.deb
 ddb9aba7138409fa4d5fe49e8e8a0758 2265698 debug extra nginx-naxsi-dbg_1.2.1-2.2+wheezy4_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJWu6/lAAoJEAVMuPMTQ89EKRcP+wc2eq0U34r7D0i3qyA+EZNb
lANy77m0ZjFvDgsClf3saei0Tzj6p7WD2+ghSLccwhDmKEcZkKoJKYTPZLFYLMOh
w0gTCTIo40nodNM8U9DEf7jtdrV44cVAgFt57Tpas7pF2VIZs+d5Eq9v0FZ9Uu5/
Hbhzxb2n2sbz6iKsiaxzkgHKsGtJjFYZpJfpJQl6GIcNxnVEflStierq8sSThb8/
cOtqjL6TQ47uK/jr0+9p0sfCtZMnlx2qZDpGTEkVOpKKIQz3BkxlUceJXX/UUhG5
rgmI+oNZPRvSwvuJIeucHj2HK0pfseSEceWjg6mOO/3XDrDMtnFAfjbCn4k8uGSS
0vPOapLv9T7w2BRPFz/hzSCfQdfcArrd266+61BMNvf3q/O5Gcb6Ecjm52pHtjsW
Bmi2eEKq9b6ndAA9H+rIWO2B6z+fSbINbe2bHyoK4+L0pEdPFf+qDXB5Hr7dNxug
9zCXYXz8Dw8j110/WWUZAbIimjopSeebg8LTBDk5nMLQg6ZvgK9nDjDOAkuebfWX
KyEsBkcq0mmduCUmvJUKtQj54HgDPwGG/WYFUjTFYdZQ9nlbytl0SJHl7n8axl+Y
lJfp8dhR/sVw49AA+/wP1KcS6A40Unt5/AOaSMUSzmab7sY2FE2ljP63vJrWAgbh
5Fmg9qMaKETmYf5cVgo9
=NX+h
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 13 Mar 2016 07:26:00 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 17:08:40 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.