Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
nginx could be made to expose sensitive information over the network.
Software Description:
- nginx: small, powerful, scalable web/proxy server
Details:
Antoine Delignat-Lavaud and Karthikeyan Bhargavan discovered that nginx
incorrectly reused cached SSL sessions. An attacker could possibly use this
issue in certain configurations to obtain access to information from a
different virtual host.
The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: nginx-core 1.4.6-1ubuntu3.1 nginx-extras 1.4.6-1ubuntu3.1 nginx-full 1.4.6-1ubuntu3.1 nginx-light 1.4.6-1ubuntu3.1 nginx-naxsi 1.4.6-1ubuntu3.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2351-1
CVE-2014-3616
Get the latest Linux and open source security news straight to your inbox.