diff options
author | Maxim Dounin <mdounin@mdounin.ru> | 2013-05-06 14:20:27 +0400 |
---|---|---|
committer | Maxim Dounin <mdounin@mdounin.ru> | 2013-05-06 14:20:27 +0400 |
commit | 45b587fdc7e88fcb9654254737d661bb5b7dbc83 (patch) | |
tree | 819930253d55116b4f875be733a4caa500ca6e61 | |
parent | 4997de8005630664ab35f27140e2077e818b21a7 (diff) | |
download | nginx-release-1.4.1.tar.gz nginx-release-1.4.1.zip |
nginx-1.4.1-RELEASErelease-1.4.1
-rw-r--r-- | docs/xml/nginx/changes.xml | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/docs/xml/nginx/changes.xml b/docs/xml/nginx/changes.xml index 71e069342..6a0b1af8f 100644 --- a/docs/xml/nginx/changes.xml +++ b/docs/xml/nginx/changes.xml @@ -5,6 +5,28 @@ <change_log title="nginx"> +<changes ver="1.4.1" date="07.05.2013"> + +<change type="security"> +<para lang="ru"> +при обработке специально созданного запроса +мог перезаписываться стек рабочего процесса, +что могло приводить к выполнению произвольного кода (CVE-2013-2028); +ошибка появилась в 1.3.9.<br/> +Спасибо Greg MacManus, iSIGHT Partners Labs. +</para> +<para lang="en"> +a stack-based buffer overflow might occur in a worker process +while handling a specially crafted request, +potentially resulting in arbitrary code execution (CVE-2013-2028); +the bug had appeared in 1.3.9.<br/> +Thanks to Greg MacManus, iSIGHT Partners Labs. +</para> +</change> + +</changes> + + <changes ver="1.4.0" date="24.04.2013"> <change type="bugfix"> |