lp:ubuntu/lucid-security/nginx

Created by James Westby and last modified
Get this branch:
bzr branch lp:ubuntu/lucid-security/nginx
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Status:
Development

Recent revisions

33. By Thomas Ward

* Security update (closes LP: #956150):
   * Patch to fix 'Use-after-free vulnerability' (CVE-2012-1180).
   * Patch to fix 'Heap-based buffer overflow in compression-pointer
     processing in core/ngx_resolver.c' (CVE-2011-4315).

32. By Neal Poole

* SECURITY UPDATE:
  - debian/patches/nginx-null_byte_in_urls.patch: Merge r3528 from
    upstream repository to mitigate potential null byte vulnerability
    (LP: #783508)

31. By Daniel Hahler

Re-enable http_realip_module (debian/rules).
Apparently got lost by accident for the 0.7 branch (Closes: #507419)
LP: #268750

30. By Daniel Hahler

* Merge from debian testing. (LP: #531655) Remaining changes:
  - Add a UFW profile set:
    + debian/nginx.ufw.profile: Added.
    + debian/control: nginx: Suggests ufw.
    + debian/dirs: Add 'etc/ufw/applications.d'
    + debian/rules: Add install rule for the nginx UFW profile.
  - Install html files.
    - debian/dirs: Add 'var/www/nginx-default'.
    - debian/nginx.install: Add 'html/* var/www/nginx-default'.

29. By Mathieu Trudel-Lapierre

* Merge from debian testing (LP: #513099), remaining changes:
  - Install html files.
    - debian/dirs: Add 'var/www/nginx-default'.
    - debian/nginx.install: Add 'html/* var/www/nginx-default'.
  - Add a UFW profile set:
    + debian/nginx.ufw.profile: Added.
    + debian/control: nginx: Suggests ufw.
    + debian/dirs: Add 'etc/ufw/applications.d'
    + debian/rules: Add install rule for the nginx UFW profile.
* Fixes CVE-2009-3555, as per changelog entry in 0.7.64-1. (LP: #511681)

28. By Andres Rodriguez

* Merge from debian testing (LP: #490450), remaining changes:
  - Install html files.
    - debian/dirs: Add 'var/www/nginx-default'.
    - debian/nginx.install: Add 'html/* var/www/nginx-default'.
  - Added a UFW profile set: (LP: #308695)
    + debian/nginx.ufw.profile: Added.
    + debian/control: nginx: Suggests ufw.
    + debian/dirs: Added 'etc/ufw/applications.d'
    + debian/rules: Added install rule for the nginx UFW profile.

27. By Daniel Hahler

* Merge from debian unstable (LP: #450874), remaining changes:
  - Install html files.
    - debian/dirs: Add 'var/www/nginx-default'.
    - debian/nginx.install: Add 'html/* var/www/nginx-default'.
  - Added a UFW profile set: (LP: #308695)
    + debian/nginx.ufw.profile: Added.
    + debian/control: nginx: Suggests ufw.
    + debian/dirs: Added 'etc/ufw/applications.d'
    + debian/rules: Added install rule for the nginx UFW profile.
* Closes: LP: #260005, LP: #440888

26. By Andres Rodriguez

* Install html files.
  - debian/dirs: Add 'var/www/nginx-default'.
  - debian/nginx.install: Add 'html/* var/www/nginx-default'.
* SECURITY UPDATE (CVE-2009-2629): Buffer underflow vulnerability, which
  allows remote attackers to execute arbitrary code via crafted HTTP
  request. (LP: #430064)
  - src/http/ngx_http_parse.c patched.

25. By Andres Rodriguez

* Merge from debian unstable (LP: #416635), remaining changes:
  - Readd status action to init script:
    + debian/init.d:
      - Add sourcing to '. /lib/lsb/init-functions'
      - Add 'status' action.
    + debian/control: Add Depend on lsb >= 3.2-14, which has the
      statuc_of_proc() function.
  - Added a UFW profile set: (LP: #308695)
    + debian/nginx.ufw.profile: Added.
    + debian/control: nginx: Suggests ufw.
    + debian/dirs: Added 'etc/ufw/applications.d'
    + debian/rules: Added install rule for the nginx UFW profile.
  - Added support for gzip_static module: (LP: #346010)
    + debian/rules: Added '--with-http_gzip_static_module' to configure.

24. By Andres Rodriguez

* Readd status action to init script: (LP: #251985)
  - debian/init.d:
    + Add sourcing to '. /lib/lsb/init-functions'
    + Add 'status' action.
  - debian/control: Add Depend on lsb >= 3.2-14, which has the
    statuc_of_proc() function.
* Added a UFW profile set: (LP: #308695)
  - debian/nginx.ufw.profile: Added.
  - debian/control: nginx: Suggests ufw.
  - debian/dirs: Added 'etc/ufw/applications.d'
  - debian/rules: Added install rule for the nginx UFW profile.
* Added support for gzip_static module: (LP: #346010)
  - debian/rules: Added '--with-http_gzip_static_module' to configure.
* debian/control: Update Maintainer field to match Ubuntu Developers.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/oneiric/nginx
This branch contains Public information 
Everyone can see this information.

Subscribers