Page 1 of 1

nginx Security Update

Posted: Fri Sep 19, 2014 1:04 pm
by Imaging
FYI, a recent nginx update that impacts a number of branches:

SSL session reuse vulnerability
Severity: medium
CVE-2014-3616
Not vulnerable: 1.7.5+, 1.6.2+
Vulnerable: 0.5.6-1.7.4

http://nginx.org/en/security_advisories.html

Can the atomic rpms be updated to 1.7.5 or 1.6.2 (for both CentOS 5.x and 6.x)?

Thank you.

Re: nginx Security Update

Posted: Tue Sep 23, 2014 3:06 pm
by scott
Updates are going out today, thanks for posting the request. I check as frequently as I can, but sometimes other stuff gets in the way. Its really helpful when we get these kinds of updates to ensure nothing falls through the gaps. Especially when its a vulnerability update

Re: nginx Security Update

Posted: Tue Sep 23, 2014 3:57 pm
by Imaging
Great, thanks!