Debian Security Advisory
DSA-4921-1 nginx -- security update
- Date Reported:
- 28 May 2021
- Affected Packages:
- nginx
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 989095.
In Mitre's CVE dictionary: CVE-2021-23017. - More information:
-
Luis Merino, Markus Vervier and Eric Sesterhenn discovered an off-by-one in Nginx, a high-performance web and reverse proxy server, which could result in denial of service and potentially the execution of arbitrary code.
For the stable distribution (buster), this problem has been fixed in version 1.14.2-2+deb10u4.
We recommend that you upgrade your nginx packages.
For the detailed security status of nginx please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nginx