Summary
The remote host is missing updates announced in
advisory GLSA 201203-22.
Solution
All nginx users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=www-servers/nginx-1.0.14'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201203-22 http://bugs.gentoo.org/show_bug.cgi?id=293785
http://bugs.gentoo.org/show_bug.cgi?id=293786
http://bugs.gentoo.org/show_bug.cgi?id=293788
http://bugs.gentoo.org/show_bug.cgi?id=389319
http://bugs.gentoo.org/show_bug.cgi?id=408367
Insight
Multiple vulnerabilities have been found in nginx, the worst of which may allow execution of arbitrary code.
Severity
Classification
-
CVE CVE-2009-3555, CVE-2009-3896, CVE-2009-3898, CVE-2011-4315, CVE-2012-1180 -
CVSS Base Score: 5.8
AV:N/AC:M/Au:N/C:N/I:P/A:P
Related Vulnerabilities