Debian Security Advisory

DSA-3592-1 nginx -- security update

Date Reported:
01 Jun 2016
Affected Packages:
nginx
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-4450.
More information:

It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a temporary file might result in denial of service: Malformed requests could crash worker processes.

For the stable distribution (jessie), this problem has been fixed in version 1.6.2-5+deb8u2.

For the unstable distribution (sid), this problem has been fixed in version 1.10.1-1.

We recommend that you upgrade your nginx packages.