shield Security update for nginx-1.0
slewyst13-nginx-1.0-9834


This update for nginx fixes the following security issue: * A virtual host confusion issue in nginx allowed HTTPS connections for one origin to be redirected to the virtual host of a different origin. This could have lead to a variety of issues, such as cookie theft and session hijacking. It could have been triggered from a cross-site scripting flaw, tricking a user into visiting a malicious URL, and so on. (CVE-2014-3616) Security Issues: * CVE-2014-3616 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3616>

  • Release Date
    Oct 6 2014
  • References
    Bugzilla: 897029
    CVEs: CVE-2014-3616
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

SUSE WebYaST 1.3 unknown
  • Packages
    nginx-1.0
    HTTP server
    1.0.15-0.10.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    nginx-1.0
    HTTP server
    1.0.15-0.10.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    nginx-1.0
    HTTP server
    1.0.15-0.10.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    nginx-1.0
    HTTP server
    1.0.15-0.10.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    nginx-1.0
    HTTP server
    1.0.15-0.10.1 lock rpm