[USN-2351-1] nginx vulnerability

Severity Medium
Affected Packages 9
CVEs 1

nginx could be made to expose sensitive information over the network.

Antoine Delignat-Lavaud and Karthikeyan Bhargavan discovered that nginx
incorrectly reused cached SSL sessions. An attacker could possibly use this
issue in certain configurations to obtain access to information from a
different virtual host.

ID
USN-2351-1
Severity
medium
URL
https://ubuntu.com/security/notices/USN-2351-1
Published
2014-09-22T16:32:19
(10 years ago)
Modified
2014-09-22T16:32:19
(10 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/nginx?distro=trusty ubuntu nginx < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-naxsi?distro=trusty ubuntu nginx-naxsi < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-naxsi-ui?distro=trusty ubuntu nginx-naxsi-ui < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-light?distro=trusty ubuntu nginx-light < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-full?distro=trusty ubuntu nginx-full < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-extras?distro=trusty ubuntu nginx-extras < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-doc?distro=trusty ubuntu nginx-doc < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-core?distro=trusty ubuntu nginx-core < 1.4.6-1ubuntu3.1 trusty
Affected pkg:deb/ubuntu/nginx-common?distro=trusty ubuntu nginx-common < 1.4.6-1ubuntu3.1 trusty
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...