Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 13 Apr 2012 23:23:09 -0700
From:      Jason Helfman <jgh@FreeBSD.org>
To:        "Sergey A. Osokin" <osa@FreeBSD.org>
Cc:        cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org, ports-committers@FreeBSD.org
Subject:   Re: cvs commit: ports/www/nginx-devel Makefile distinfo
Message-ID:  <20120414062309.GA15958@dormouse.experts-exchange.com>
In-Reply-To: <201204131217.q3DCH5LP085407@repoman.freebsd.org>
References:  <201204131217.q3DCH5LP085407@repoman.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, Apr 13, 2012 at 12:17:05PM +0000, Sergey A. Osokin thus spake:
>osa         2012-04-13 12:17:05 UTC
>
>  FreeBSD ports repository
>
>  Modified files:
>    www/nginx-devel      Makefile distinfo
>  Log:
>  Security update from 1.1.18 to 1.1.19.
>
>  <ChangeLog>
>
>  *) Security: specially crafted mp4 file might allow to overwrite memory
>     locations in a worker process if the ngx_http_mp4_module was used,
>     potentially resulting in arbitrary code execution (CVE-2012-2089).
>     Thanks to Matthew Daley.
>
>  *) Bugfix: nginx/Windows might be terminated abnormally.
>     Thanks to Vincent Lee.
>
>  *) Bugfix: nginx hogged CPU if all servers in an upstream were marked as
>     "backup".
>
>  *) Bugfix: the "allow" and "deny" directives might be inherited
>     incorrectly if they were used with IPv6 addresses.
>
>  *) Bugfix: the "modern_browser" and "ancient_browser" directives might
>     be inherited incorrectly.
>
>  *) Bugfix: timeouts might be handled incorrectly on Solaris/SPARC.
>
>  *) Bugfix: in the ngx_http_mp4_module.
>
>  </ChangeLog>
>
>  Revision  Changes    Path
>  1.444     +1 -1      ports/www/nginx-devel/Makefile
>  1.388     +2 -2      ports/www/nginx-devel/distinfo
>
>http://www.FreeBSD.org/cgi/cvsweb.cgi/ports/www/nginx-devel/Makefile.diff?&r1=1.443&r2=1.444&f=h
>http://www.FreeBSD.org/cgi/cvsweb.cgi/ports/www/nginx-devel/distinfo.diff?&r1=1.387&r2=1.388&f=h
>

Is there a vuxml entry that is being put together for this update?

Thanks.

- -jgh

- -- 
Jason Helfman         | FreeBSD Committer
jgh@FreeBSD.org       | http://people.freebsd.org/~jgh
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.18 (FreeBSD)

iQEcBAEBAgAGBQJPiRfNAAoJECBZmmNBUNPcURIIALRWC/eQ+oPfJ6ThsuS0h1iS
60JfH1hHPHrRUhz/tBdVeOqK7tbRnmTArF+hiV4FtD3eCHUpLfp6Hn57FZfXzYtg
Fqhb9+QSyKiCG7QUmi6DKsuz/Nzd825Ahrzb4DCLgGdwMnyMjyMJadBfvE4V21Yd
DAhN5K6a5FF8mOlN2Dz13WtpTIPWhaflPW0wSCuUrQ3zT57DaS2u9G/GlFmWixSC
NlkvM2PBm+KgI/WUfkQAkWO95i4XSvo0Rz5AdXENsEz2pyhEHnYaVLBuiMQ/iLzZ
7jds1S4v6rQVrwOKtAktX4r9JojTpBUMsNpX7i4VKVbpdShrB99WwM7+1UKsm60=
=UIRv
-----END PGP SIGNATURE-----



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20120414062309.GA15958>