[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 1884-1] New nginx packages fix arbitrary code execution



Hi,
* Nico Golde <debian-security+ml@ngolde.de> [2009-09-14 22:53]:
> * Jean Christophe André <jean-christophe.andre@auf.org> [2009-09-14 20:35]:
> > Nico Golde a écrit :
> > > For the stable distribution (lenny), this problem has been fixed in
> > version 0.6.32-3+lenny2.
> > There is some serious dependency problem forbidding the upgrade:
> > 
> > www:~# LANG= apt-cache show nginx
> > Architecture: i386
> > Version: 0.6.32-3+lenny2
> > Depends: libc6 (>= 2.3.4), libpcre3 (>= 7.7), libssl0.9.8 (>= 0.9.8f-5),
> > zlib1g
> > (>= 1:1.1.4)
> > 
> > www:~# LANG= apt-cache policy libpcre3
> > libpcre3:
> >   Installed: 7.6-2.1
> >   Candidate: 7.6-2.1
> >   Version table:
> >  *** 7.6-2.1 0
> > 
> > Did I miss something?
> 
> There was a problem with the build chroot I didn't notice 
> when installing the test packages. I pinged a member of the 
> release team to schedule a binNMU. Thanks for the heads-up!

Fixed, use 0.6.32-3+lenny2+b1.

Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - nion@jabber.ccc.de - GPG: 0xA0A0AAAA
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpEIhQjFFeY5.pgp
Description: PGP signature


Reply to: