[Pkg-nginx-maintainers] Bug#948579: nginx: CVE-2019-20372

Salvatore Bonaccorso carnil at debian.org
Fri Jan 10 13:06:58 GMT 2020


Source: nginx
Version: 1.16.1-2
Severity: important
Tags: security upstream
Control: found -1 1.14.2-2+deb10u1

Hi,

The following vulnerability was published for nginx.

CVE-2019-20372[0]:
| NGINX before 1.17.7, with certain error_page configurations, allows
| HTTP request smuggling, as demonstrated by the ability of an attacker
| to read unauthorized web pages in environments where NGINX is being
| fronted by a load balancer.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-20372
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20372
[1] https://bertjwregeer.keybase.pub/2019-12-10%20-%20error_page%20request%20smuggling.pdf
[2] https://github.com/nginx/nginx/commit/c1be55f97211d38b69ac0c2027e6812ab8b1b94e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-nginx-maintainers mailing list