[nginx] nginx-1.10.1-RELEASE

Maxim Dounin mdounin at mdounin.ru
Tue May 31 16:27:56 UTC 2016


details:   http://hg.nginx.org/nginx/rev/7fcde9122088
branches:  stable-1.10
changeset: 6580:7fcde9122088
user:      Maxim Dounin <mdounin at mdounin.ru>
date:      Tue May 31 16:47:01 2016 +0300
description:
nginx-1.10.1-RELEASE

diffstat:

 docs/xml/nginx/changes.xml |  20 ++++++++++++++++++++
 1 files changed, 20 insertions(+), 0 deletions(-)

diffs (30 lines):

diff --git a/docs/xml/nginx/changes.xml b/docs/xml/nginx/changes.xml
--- a/docs/xml/nginx/changes.xml
+++ b/docs/xml/nginx/changes.xml
@@ -5,6 +5,26 @@
 <change_log title="nginx">
 
 
+<changes ver="1.10.1" date="31.05.2016">
+
+<change type="security">
+<para lang="ru">
+при записи тела специально созданного запроса во временный файл
+в рабочем процессе мог происходить segmentation fault
+(CVE-2016-4450);
+ошибка появилась в 1.3.9.
+</para>
+<para lang="en">
+a segmentation fault might occur in a worker process
+while writing a specially crafted request body to a temporary file
+(CVE-2016-4450);
+the bug had appeared in 1.3.9.
+</para>
+</change>
+
+</changes>
+
+
 <changes ver="1.10.0" date="26.04.2016">
 
 <change>


More information about the nginx-devel mailing list