Subject: CVS commit: pkgsrc/www/nginx-devel
From: Adam Ciarcinski
Date: 2018-11-19 12:05:14
Message id: 20181119110514.CD8F7FB1F@cvs.NetBSD.org

Log Message:
nginx-devel: updated to 1.15.6

Changes with nginx 1.15.6:

*) Security: when using HTTP/2 a client might cause excessive memory
   consumption (CVE-2018-16843) and CPU usage (CVE-2018-16844).

*) Security: processing of a specially crafted mp4 file with the
   ngx_http_mp4_module might result in worker process memory disclosure
   (CVE-2018-16845).

*) Feature: the "proxy_socket_keepalive", \ 
"fastcgi_socket_keepalive",
   "grpc_socket_keepalive", "memcached_socket_keepalive",
   "scgi_socket_keepalive", and "uwsgi_socket_keepalive" \ 
directives.

*) Bugfix: if nginx was built with OpenSSL 1.1.0 and used with OpenSSL
   1.1.1, the TLS 1.3 protocol was always enabled.

*) Bugfix: working with gRPC backends might result in excessive memory
   consumption.

Files:
RevisionActionfile
1.37modifypkgsrc/www/nginx-devel/Makefile
1.38modifypkgsrc/www/nginx-devel/distinfo