-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 20 Oct 2016 09:49:25 +0300 Source: nginx Binary: nginx nginx-doc nginx-common nginx-full nginx-full-dbg nginx-light nginx-light-dbg nginx-extras nginx-extras-dbg Architecture: source all amd64 Version: 1.9.10-1~bpo8+4 Distribution: jessie-backports Urgency: high Maintainer: Kartik Mistry <kartik@debian.org> Changed-By: Christos Trochalakis <yatiohi@ideopolis.gr> Description: nginx - small, powerful, scalable web/proxy server nginx-common - small, powerful, scalable web/proxy server - common files nginx-doc - small, powerful, scalable web/proxy server - documentation nginx-extras - nginx web/proxy server (extended version) nginx-extras-dbg - nginx web/proxy server (extended version) - debugging symbols nginx-full - nginx web/proxy server (standard version) nginx-full-dbg - nginx web/proxy server (standard version) - debugging symbols nginx-light - nginx web/proxy server (basic version) nginx-light-dbg - nginx web/proxy server (basic version) - debugging symbols Closes: 842295 Changes: nginx (1.9.10-1~bpo8+4) jessie-backports; urgency=high . [ Christos Trochalakis ] * debian/nginx-common.postinst: + CVE-2016-1247: Secure log file handling (owner & permissions) against privilege escalation attacks. /var/log/nginx is now owned by root:adm. Thanks ro Dawid Golunski for the report. Changing /var/log/nginx permissions effectively reopens #701112, since log files can be world-readable. This is a trade-off until a better log opening solution is implemented upstream (trac:376). (Closes: #842295) Checksums-Sha1: bada9fcdb0ccccac407d3cc5d7c1ca8279982668 2853 nginx_1.9.10-1~bpo8+4.dsc 754b8ef661721b5a365ff2fb691414c6d04a9fc3 647100 nginx_1.9.10-1~bpo8+4.debian.tar.xz 643dfea8dee54055014137c853940573bb476f6c 78186 nginx_1.9.10-1~bpo8+4_all.deb ac4c52ab788ec95121201cdce7794f655ce985be 89660 nginx-doc_1.9.10-1~bpo8+4_all.deb e4d78b23b1a55ac707b1b1d22a9c3af4321dd71a 99574 nginx-common_1.9.10-1~bpo8+4_all.deb df623a5684938a559783be30ace616470876534e 499952 nginx-full_1.9.10-1~bpo8+4_amd64.deb 46b17c77234132b8431f31bb4b1978cc128fce99 3571366 nginx-full-dbg_1.9.10-1~bpo8+4_amd64.deb bf08cc0b86a01f7014939ffcb4471a7148629dff 369152 nginx-light_1.9.10-1~bpo8+4_amd64.deb 5fbd2bebd672c670b57d6bd1811f049b06c80a42 2284298 nginx-light-dbg_1.9.10-1~bpo8+4_amd64.deb 0b55df4815cb919012c047ae159bdd00ebb5bd2c 690476 nginx-extras_1.9.10-1~bpo8+4_amd64.deb 6117e021f9ecdc3d3dbfdf5d6058e90a323f0112 5587810 nginx-extras-dbg_1.9.10-1~bpo8+4_amd64.deb Checksums-Sha256: 5b41779a520d3e3e6020cbe8a37b7809877e9e2e76f72c9a402e33d3b15402db 2853 nginx_1.9.10-1~bpo8+4.dsc f996860814bfa9256f5c4053924026fedc7b6370b59b22811706b1da2a926867 647100 nginx_1.9.10-1~bpo8+4.debian.tar.xz f1e32d7349acb0db071ce33b2315bd81d76be0beb5b613f9f46c119fd78bac2a 78186 nginx_1.9.10-1~bpo8+4_all.deb f4bba231315b0c7119468a7f92d415dd7bcdbcfa477021a26b6ad8f0eed3c841 89660 nginx-doc_1.9.10-1~bpo8+4_all.deb 6c6336b5d43cd5a5a1b397fc226bd0fbc3d26db94c347df3dc9f3d2ec73faa04 99574 nginx-common_1.9.10-1~bpo8+4_all.deb c9c53d78e1c7c30a9c2d3670421f813450fb363c4a7181b28984d3f38328333a 499952 nginx-full_1.9.10-1~bpo8+4_amd64.deb 888995a666b7b0e9d7ba80a66070fce30d66d2046f224f8719e3e229baef750e 3571366 nginx-full-dbg_1.9.10-1~bpo8+4_amd64.deb 76f43d5f071f22433d83c6f5fb8787ffb5311c730bdb9c5adfd945b8f5643a86 369152 nginx-light_1.9.10-1~bpo8+4_amd64.deb 0263d9258515d90c8d33d75e96634b120aca7d050c0da702cd247b470707cb4e 2284298 nginx-light-dbg_1.9.10-1~bpo8+4_amd64.deb 54d91c8709fcd1d434bfde1babfc72d96962212426ee2dec629cea246da31a6c 690476 nginx-extras_1.9.10-1~bpo8+4_amd64.deb 066d8924fb051c4595e330ddd02398d6d07f94fad646cf5e9bb13fe9ae85ff8f 5587810 nginx-extras-dbg_1.9.10-1~bpo8+4_amd64.deb Files: 24123b10eb139239dc9a34a968aed313 2853 httpd optional nginx_1.9.10-1~bpo8+4.dsc 0c49436797a03da6a15d5922be79611c 647100 httpd optional nginx_1.9.10-1~bpo8+4.debian.tar.xz 277f7d25ade1f44b30a625afc06574a7 78186 httpd optional nginx_1.9.10-1~bpo8+4_all.deb a78dea7e508e4db1b47e4490a97f7284 89660 doc optional nginx-doc_1.9.10-1~bpo8+4_all.deb d8625c558498dc582568bccc3958d7b0 99574 httpd optional nginx-common_1.9.10-1~bpo8+4_all.deb 2d5e5cdfab84bafa6bc7f29d64c6141e 499952 httpd optional nginx-full_1.9.10-1~bpo8+4_amd64.deb 995bd7a57000aa34ceaba19b11734828 3571366 debug extra nginx-full-dbg_1.9.10-1~bpo8+4_amd64.deb abb840ce3b394018535661ea6bc8df86 369152 httpd extra nginx-light_1.9.10-1~bpo8+4_amd64.deb e823d147c45438a21ca1e045d56a7cf5 2284298 debug extra nginx-light-dbg_1.9.10-1~bpo8+4_amd64.deb 8ad2dc3311eefcdbf564bed4171fd480 690476 httpd extra nginx-extras_1.9.10-1~bpo8+4_amd64.deb ba794f51244ebedbf6beb4ea1fe01ce2 5587810 debug extra nginx-extras-dbg_1.9.10-1~bpo8+4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYGiU9AAoJEBE2JgCnR+zZuYEP+gJWJyAANJKYw5rxK4V1UdWo BeOOkJArLJ6LWTbdi3s4bG+ceXU+HtMMTl++3ZLsEBvlj9zD7UsEZKM0+NrpFlcw JiBkiZAcgzebimWhBfo9GD19eNu9rb7X6IRD9DAcpJuSv5+A+daTel+soGekk4Ab /bR4/6n9JASY20+qClWXcWEETh1gQGQ0IeY/31o8SDtv1jKL95ytZpj/WWg9R2pM igBpjccw7Ydq46KavIPNMr/K1/KSelhmo08JW0/WQXgljc4CKZmlCbFrKehAaf4A hnZ54tjhDB96y4ZD4zGUpthqzCaUQQ+u0f/EXftnr4C8YhddD3nKpGc61le9CP03 TDWB1FS1DU/NhSNoQ9ex8HnVaCSXbNsVWH29QI/Rhkax/82i6A7l5jIpe6tpF87v 769d3UMyQNM8SW6/nbunUG2nFgM9hjMgMlwWi9KeP18ztK1Y4ZlUtTQqjMKyqFyp IQ3rCRMRnvxeeuCitIaSy6o3WusJsGGI945I2Fq8enmHKH6TP99VyBRjL4bLuAFs PfW1JZFwAaFBp7UFYe7PhfN3CyajAikiuyqkxa7hb8wLhcyPmgdmx8Bvok+NAj02 sd1FPE/8hyoqsl/YBLeADgw+Ow+kUNVbo7McEL40Ja7zshWsa+dZ0qRZZoWO6YtQ JQm3NRttS8YaL/4llevU =32tg -----END PGP SIGNATURE-----