• [SECURITY] [DSA 2627-1] nginx security update

    From Thijs Kinkhorst@1:229/2 to All on Sun Feb 17 12:30:01 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2627-1 [email protected] http://www.debian.org/security/ Thijs Kinkhorst February 17, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : nginx
    Vulnerability : information leak
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2012-4929
    Debian Bug : 700426

    Juliano Rizzo and Thai Duong discovered a weakness in the TLS/SSL
    protocol when using compression. This side channel attack, dubbed
    'CRIME', allows eavesdroppers to gather information to recover the
    original plaintext in the protocol. This update to nginx disables
    SSL compression.

    For the stable distribution (squeeze), this problem has been fixed in
    version 0.7.67-3+squeeze3.

    For the testing distribution (wheezy), and unstable distribution (sid),
    this problem has been fixed in version 1.1.16-1.

    We recommend that you upgrade your nginx packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.12 (GNU/Linux)

    iQEcBAEBAgAGBQJRILlaAAoJEFb2GnlAHawEajsIAJoBu1SQDZVe0N07eLgrSmYU 4l0Myci9yL1j2gPYCuvi6VTJn9gtAvRtrBbVUJo6u88Npv9WwidG20doXsarxv0G To0Bt003I5vgCCKv3rHLxjTtrOyMp3kn3/Wh/ypYPYQCn9HBH9nD/5uzCL5CBPBA zfj0VukmmOPqsm6bRzqyfXppGYw/YDX9N81F0TQRPkOj1vBmvsBfOh6xC4qUJlrz MqrLGMAQU8PNN7m1RmNQoMrZx21I9yk6GYKmsVIKq7+bg3cvQz4mQxQQYOKLTf0b FrXThxdr+81lPeKdDDrch0jNRFv1b5g6nI5FIfk71kJRR7YtauXDIXP+iXZuv00=
    =ennR
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)