Mercurial > hg > nginx
changeset 5447:7e9543faf5f0 stable-1.4 release-1.4.4
nginx-1.4.4-RELEASE
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Tue, 19 Nov 2013 15:25:24 +0400 |
parents | 988c22615014 |
children | 68e250ceb06e |
files | docs/xml/nginx/changes.xml |
diffstat | 1 files changed, 20 insertions(+), 0 deletions(-) [+] |
line wrap: on
line diff
--- a/docs/xml/nginx/changes.xml Tue Nov 19 06:57:58 2013 +0400 +++ b/docs/xml/nginx/changes.xml Tue Nov 19 15:25:24 2013 +0400 @@ -5,6 +5,26 @@ <change_log title="nginx"> +<changes ver="1.4.4" date="19.11.2013"> + +<change type="security"> +<para lang="ru"> +символ, следующий за незакодированным пробелом в строке запроса, +обрабатывался неправильно (CVE-2013-4547); +ошибка появилась в 0.8.41.<br/> +Спасибо Ivan Fratric из Google Security Team. +</para> +<para lang="en"> +a character following an unescaped space in a request line +was handled incorrectly (CVE-2013-4547); +the bug had appeared in 0.8.41.<br/> +Thanks to Ivan Fratric of the Google Security Team. +</para> +</change> + +</changes> + + <changes ver="1.4.3" date="08.10.2013"> <change type="bugfix">