UbuntuUpdates.org

Package "nginx"

Name: nginx

Description:

small, powerful, scalable web/proxy server

Latest version: 1.24.0-2ubuntu7.3
Release: noble (24.04)
Level: security
Repository: main
Homepage: https://nginx.org

Links


Download "nginx"


Other versions of "nginx" in Noble

Repository Area Version
base universe 1.24.0-2ubuntu7
base main 1.24.0-2ubuntu7
security universe 1.24.0-2ubuntu7.3
updates main 1.24.0-2ubuntu7.3
updates universe 1.24.0-2ubuntu7.3
proposed main 1.24.0-2ubuntu7.2
proposed universe 1.24.0-2ubuntu7.2
PPA: Nginx from nginx.org 1.26.3-1~noble

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.24.0-2ubuntu7.3 2025-04-01 14:07:23 UTC

  nginx (1.24.0-2ubuntu7.3) noble-security; urgency=medium

  * SECURITY UPDATE: Session resumption
    - debian/patches/CVE-2025-23419.patch: added restriction for TLSv1.3
      cross-SNI session resumption in files src/http/ngx_http_request.c.
    - CVE-2025-23419

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 31 Mar 2025 15:38:37 -0300

Source diff to previous version
CVE-2025-23419 When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate

Version: 1.24.0-2ubuntu7.1 2024-09-16 15:07:09 UTC

  nginx (1.24.0-2ubuntu7.1) noble-security; urgency=medium

  * SECURITY UPDATE: DoS in ngx_http_mp4_module
    - debian/patches/CVE-2024-7347-1.patch: fixed buffer underread while
      updating stsz atom in src/http/modules/ngx_http_mp4_module.c.
    - debian/patches/CVE-2024-7347-2.patch: reject unordered chunks in stsc
      atom in src/http/modules/ngx_http_mp4_module.c.
    - CVE-2024-7347

 -- Marc Deslauriers <email address hidden> Tue, 10 Sep 2024 09:27:33 -0400

CVE-2024-7347 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resu



About   -   Send Feedback to @ubuntu_updates