[nginx] nginx-1.4.4-RELEASE

Maxim Dounin mdounin at mdounin.ru
Tue Nov 19 14:57:26 UTC 2013

details:   http://hg.nginx.org/nginx/rev/7e9543faf5f0
branches:  stable-1.4
changeset: 5447:7e9543faf5f0
user:      Maxim Dounin <mdounin at mdounin.ru>
date:      Tue Nov 19 15:25:24 2013 +0400


 docs/xml/nginx/changes.xml |  20 ++++++++++++++++++++
 1 files changed, 20 insertions(+), 0 deletions(-)

diffs (30 lines):

diff --git a/docs/xml/nginx/changes.xml b/docs/xml/nginx/changes.xml
--- a/docs/xml/nginx/changes.xml
+++ b/docs/xml/nginx/changes.xml
@@ -5,6 +5,26 @@
 <change_log title="nginx">
+<changes ver="1.4.4" date="19.11.2013">
+<change type="security">
+<para lang="ru">
+символ, следующий за незакодированным пробелом в строке запроса,
+обрабатывался неправильно (CVE-2013-4547);
+ошибка появилась в 0.8.41.<br/>
+Спасибо Ivan Fratric из Google Security Team.
+<para lang="en">
+a character following an unescaped space in a request line
+was handled incorrectly (CVE-2013-4547);
+the bug had appeared in 0.8.41.<br/>
+Thanks to Ivan Fratric of the Google Security Team.
 <changes ver="1.4.3" date="08.10.2013">
 <change type="bugfix">

More information about the nginx-devel mailing list