Summary
The remote host is missing updates announced in
advisory GLSA 200909-18.
Solution
All nginx 0.5.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose =www-servers/nginx-0.5.38
All nginx 0.6.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose =www-servers/nginx-0.6.39
All nginx 0.7.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose =www-servers/nginx-0.7.62
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200909-18 http://bugs.gentoo.org/show_bug.cgi?id=285162
Insight
A buffer underflow vulnerability in the request URI processing of nginx might enable remote attackers to execute arbitrary code or cause a Denial
of Service.
Severity
Classification
-
CVE CVE-2009-2629 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities