Lucene search

K
mageiaGentoo FoundationMGASA-2014-0427
HistoryOct 28, 2014 - 2:33 p.m.

Updated nginx packages fix CVE-2014-3616

2014-10-2814:33:36
Gentoo Foundation
advisories.mageia.org
20

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

61.6%

Updated nginx package fixes security vulnerability: Antoine Delignat-Lavaud and Karthikeyan Bhargavan discovered that it was possible to reuse cached SSL sessions in unrelated contexts, allowing virtual host confusion attacks in some configurations by an attacker in a privileged network position (CVE-2014-3616).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchnginx< 1.2.9-1.3nginx-1.2.9-1.3.mga3
Mageia4noarchnginx< 1.4.7-1.1nginx-1.4.7-1.1.mga4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

61.6%