Ubuntu Security Notice 4235-2 - USN-4235-1 fixed a vulnerability in nginx. This update provides the corresponding update for Ubuntu 14.04 ESM. Bert JW Regeer and Francisco Oca Gonzalez discovered that nginx incorrectly handled certain error_page configurations. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks and access resources contrary to expectations. Various other issues were also addressed.
f27f4f464dca0131a740388b68a10b2b2016cf4c60d9b6cb1e1399592aeffdcd
==========================================================================
Ubuntu Security Notice USN-4235-2
January 15, 2020
nginx vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 ESM
Summary:
nginx could be made to expose sensitive information over the
network.
Software Description:
- nginx: small, powerful, scalable web/proxy server
Details:
USN-4235-1 fixed a vulnerability in nginx. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Bert JW Regeer and Francisco Oca Gonzalez discovered that nginx incorrectly
handled certain error_page configurations. A remote attacker could possibly
use this issue to perform HTTP request smuggling attacks and access
resources contrary to expectations.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 ESM:
nginx-common 1.4.6-1ubuntu3.9+esm1
nginx-core 1.4.6-1ubuntu3.9+esm1
nginx-extras 1.4.6-1ubuntu3.9+esm1
nginx-full 1.4.6-1ubuntu3.9+esm1
nginx-light 1.4.6-1ubuntu3.9+esm1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4235-2
https://usn.ubuntu.com/4235-1
CVE-2019-20372