Canonical solves the Nginx vulnerability in Ubuntu14.04LTS

Source: Internet
Author: User
Users should update their systems to fix this vulnerability! Canonical has published details about the nginx vulnerability that affects Ubuntu14.04LTS (TrustyTahr) in the Security Bulletin. This problem has been fixed. Ubuntu developers have fixed a small nginx vulnerability. They explained that nginx may have been used to expose sensitive information on the network. According to the Security Bulletin, & ldquo; AntoineDelignat-Lavau

Users should update their systems to fix this vulnerability!

Canonical has published details about the nginx vulnerability that affects Ubuntu 14.04 LTS (Trusty Tahr) in the Security Bulletin. The problem has been fixed.

Ubuntu developers have fixed a small nginx vulnerability. They explained that nginx may have been used to expose sensitive information on the network.

According to the Security Bulletin, "Antoine Delignat-Lavaud and Karthikeyan Bhargavan found that nginx mistakenly reused the cached SSL session. Attackers may exploit this issue to obtain information from different virtual hosts under specific configurations.

For a more detailed description of these problems, you can see the Canonical Security Bulletin. You should upgrade your Linux release to solve this problem.

This problem can be solved by upgrading the system to the latest nginx package (and dependent v package. To apply the patch, you can directly run the upgrade management program.

If you do not want to use the Software Updater, open the terminal and enter the following command (root permission required ):

  1. Sudo apt-get update
  2. Sudo apt-get dist-upgrade

In general, a standard system update will make necessary changes. To apply this patch, you do not have to restart your computer.

-------------------------------------- Split line --------------------------------------

CentOS 6.2 Deployment Nginx + MySQL + PHP http://www.linuxidc.com/Linux/2013-09/90020.htm

Build a WEB server http://www.linuxidc.com/Linux/2013-09/89768.htm with Nginx

Build a Web server http://www.linuxidc.com/Linux/2013-09/89692.htm Based on Linux6.3 + Nginx1.2 + PHP5 + MySQL5.5

Nginx Performance Tuning http://www.linuxidc.com/Linux/2013-09/89656.htm in CentOS 6.3

Configure Nginx to load ngx_pagespeed module http://www.linuxidc.com/Linux/2013-09/89657.htm under CentOS 6.3

CentOS 6.4 install and configure Nginx + Pcre + php-fpm http://www.linuxidc.com/Linux/2013-08/88984.htm

Nginx installation configuration use notes http://www.linuxidc.com/Linux/2014-07/104499.htm

Nginx log filtering using ngx_log_if does not record specific log http://www.linuxidc.com/Linux/2014-07/104686.htm

-------------------------------------- Split line --------------------------------------

Nginx details: Click here
Nginx: Click here

For more information about Ubuntu, see Ubuntu special page http://www.linuxidc.com/topicnews.aspx? Tid = 2

This article permanently updates the link address: Http://www.linuxidc.com/Linux/2014-09/107333.htm

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.