Debian: DSA-2627-1: nginx security update
Debian: DSA-2627-1: nginx security update
Juliano Rizzo and Thai Duong discovered a weakness in the TLS/SSL protocol when using compression. This side channel attack, dubbed 'CRIME', allows eavesdroppers to gather information to recover the original plaintext in the protocol. This update to nginx disables
- ------------------------------------------------------------------------- Debian Security Advisory DSA-2627-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Thijs Kinkhorst February 17, 2013 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nginx Vulnerability : information leak Problem type : remote Debian-specific: no CVE ID : CVE-2012-4929 Debian Bug : 700426 Juliano Rizzo and Thai Duong discovered a weakness in the TLS/SSL protocol when using compression. This side channel attack, dubbed 'CRIME', allows eavesdroppers to gather information to recover the original plaintext in the protocol. This update to nginx disables SSL compression. For the stable distribution (squeeze), this problem has been fixed in version 0.7.67-3+squeeze3. For the testing distribution (wheezy), and unstable distribution (sid), this problem has been fixed in version 1.1.16-1. We recommend that you upgrade your nginx packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.