MGASA-2014-0427

Source
https://advisories.mageia.org/MGASA-2014-0427.html
Import Source
https://advisories.mageia.org/MGASA-2014-0427.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0427
Related
Published
2014-10-28T11:33:36Z
Modified
2014-10-28T11:12:28Z
Summary
Updated nginx packages fix CVE-2014-3616
Details

Updated nginx package fixes security vulnerability:

Antoine Delignat-Lavaud and Karthikeyan Bhargavan discovered that it was possible to reuse cached SSL sessions in unrelated contexts, allowing virtual host confusion attacks in some configurations by an attacker in a privileged network position (CVE-2014-3616).

References
Credits

Affected packages

Mageia:3 / nginx

Package

Name
nginx
Purl
pkg:rpm/mageia/nginx?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.9-1.3.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / nginx

Package

Name
nginx
Purl
pkg:rpm/mageia/nginx?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.7-1.1.mga4

Ecosystem specific

{
    "section": "core"
}