Path to this page:
Subject: CVS commit: pkgsrc/www/nginx
From: Adam Ciarcinski
Date: 2021-06-01 12:53:46
Message id: 20210601105346.9FC57FA95@cvs.NetBSD.org
Log Message:
nginx: updated to 1.20.1
Changes with nginx 1.20.1
*) Security: 1-byte memory overwrite might occur during DNS server
response processing if the "resolver" directive was used, allowing an
attacker who is able to forge UDP packets from the DNS server to
cause worker process crash or, potentially, arbitrary code execution
(CVE-2021-23017).
nginx-rtmp-module v1.2.2:
Fixed segfaults.
Files: