[CLSA-2022:1650377152] Fix CVE(s): CVE-2020-11724
Type:
security
Severity:
moderate
Release date:
2022-04-19 14:05:52 UTC
Description:
* SECURITY UPDATE: HTTP request smuggling in Lua module - debian/modules/nginx-lua: Fix parsing HTTP headers in the ngx.location.capture API (porting an upstream patch 9ab38e8ee35fc08a57636b1b6190dca70b0076fa from https://github.com/openresty/lua-nginx-module) - CVE-2020-11724
Updated packages:
  • nginx_1.10.3-0ubuntu0.16.04.8+tuxcare.els2_all.deb
    sha:d964b0daf679afc68ad62f3635af0af79946ddfe
  • nginx-common_1.10.3-0ubuntu0.16.04.8+tuxcare.els2_all.deb
    sha:f1c7fd40e18bff6d99c6d6336f53281681e3ad35
  • nginx-core_1.10.3-0ubuntu0.16.04.8+tuxcare.els2_amd64.deb
    sha:d80989544804c3529200f184883430356ead88f5
  • nginx-doc_1.10.3-0ubuntu0.16.04.8+tuxcare.els2_all.deb
    sha:f7d5abcfc55f36f307c50ad8082f7e4e8bf710c5
  • nginx-extras_1.10.3-0ubuntu0.16.04.8+tuxcare.els2_amd64.deb
    sha:b5e4a629091726861b906b8a908383ce7c4ef0b8
  • nginx-full_1.10.3-0ubuntu0.16.04.8+tuxcare.els2_amd64.deb
    sha:03368eac2f0d70ce5dbf62783e347e9fc62b3a89
  • nginx-light_1.10.3-0ubuntu0.16.04.8+tuxcare.els2_amd64.deb
    sha:b9d5159c103ac1b3dfaeb90d0a2ae9efe2f4233e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.