A flaw in the custom DNS resolver of nginx could lead to a
heap based buffer overflow which could potentially allow
attackers to execute arbitrary code or to cause a Denial of
Service (bnc#731084, CVE-2011-4315).
Special Instructions and Notes:
Please reboot the system after installing this update.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.4:
zypper in -t patch nginx-0.8-5467
To bring your system up-to-date, use "zypper patch".
- openSUSE 11.4 (i586 x86_64):
nginx-0.8-0.8.53-4.9.1
https://www.suse.com/security/cve/CVE-2011-4315.html
--
Get the latest Linux and open source security news straight to your inbox.