Merge nginx 1.4.1-1 (universe) from Debian unstable (main)

Bug #1177919 reported by Thomas Ward
26
This bug affects 3 people
Affects Status Importance Assigned to Milestone
nginx (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync nginx 1.4.1-1 (universe) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * debian/patches/ubuntu-branding.patch: Add ubuntu branding
    to server_tokens.
  * debian/patches/ubuntu-branding.patch: Add ubuntu branding
    to server_tokens.
  * debian/conf/sites-available/default:
    * Modify default site configuration file to correct a typo
      that prevented out-of-the-box usability (LP: #1162177)
  * debian/conf/sites-available/default:
    * Modify default site default configuration file to bind to IPv6
      only for IPv6 default listen statement (LP: #1132678)

The ubuntu delta is for 1.2.6-1. This is being replaced by 1.4.1-1 from Unstable
which is a newer release and addresses a lot of bugs, and a few CVEs.

Changelog entries since current saucy version 1.2.6-1ubuntu3:

nginx (1.4.1-1) unstable; urgency=low

  * New upstream release:
    + Fixes arbitrary code execution (CVE-2013-2028).
  * Uploaded to unstable.
  * debian/control:
    + Updated Standards-Version to 3.9.4

 -- Kartik Mistry <email address hidden> Tue, 07 May 2013 19:53:46 +0530

nginx (1.4.0-2) experimental; urgency=low

  [ Ondřej Surý ]
  * debian/modules/:
    + Updated nginx-echo, nginx-cache-purge and naxsi modules.
    + Removed useless .gitignore, .gitmodules files.

  [ Kartik Mistry ]
  * debian/modules/nginx-upload:
    + This module no longer works with 1.3.x and above. Removed as of now.
  * debian/modules/ngx-fancyindex:
    + Added Fancy Indexes module (Closes: #704210)
  * debian/copyright:
    + Fixed path for modules in Files: field.
    + Updated copyright for debian/*
  * debian/rules:
    + Enabled spdy module (Closes: #706195).
  * debian/control:
    + Suggests: fcgiwrap (Closes: #701508).

  [ Cyril Lavier ]
  * debian/conf/naxsi-ui.conf:
    + Added configuration file for nginx-naxsi-ui using SQLite
      (Closes: #699678).
  * debian/nginx-naxsi-ui.config, debian/nginx-naxsi-ui.postinst,
    debian/nginx-naxsi-ui.postrm, debian/nginx-naxsi-ui.prerm,
    debian/nginx-naxsi-ui.templates:
    + Removed these files as they are not necessary anymore with the
      database engine switching from MySQL to SQLite.
  * debian/control:
    + Removed dependencies against MySQL.
  * debian/rules, debian/modules/ngx_http_substitutions_filter_module,
    debian/README.Modules-versions:
    + Added http_substitutions_filter module. (Closes: #706456)

 -- Kartik Mistry <email address hidden> Wed, 01 May 2013 10:48:43 +0530

nginx (1.4.0-1) experimental; urgency=low

  [ Kartik Mistry ]
  * New upstream release (Closes: #706127).
  * debian/rules, debian/modules/:
    + Removed chunkin-nginx-module as it no longer supported for nginx 1.3.9+
    + Updated nginx-lua module to 0.8.0
    + Patched nginx-upload module as described in modules/README file.
  * Refreshed debian/patches/perl-use-dpkg-buildflags.patch
  * debian/logrotate:
    + Set default log to keep for 52 weeks instead of 52 days. Thanks to
      RjY <email address hidden> for patch (Closes: #696440)
  * debian/rules:
    + Added cache purge module to nginx-extras.
  * debian/control:
    + Suggests: nginx-docs. Thanks to colliar <email address hidden> for
      reporting bug (Closes: #702923)
  * debian/copyright:
    + Updated copyright year.
    + Fixed broken license text.

  [ Michael Lustfield ]
  * debian/conf/sites-available/default:
    + Added ipv6_only=on to default server block. (Closes: #700857)
    + Added default_server to ipv4 default server block. Now matches ipv6.
  * debian/rules:
    + Removed obsolete --with-md5 and --with-sha1

 -- Kartik Mistry <email address hidden> Thu, 25 Apr 2013 12:51:45 +0530

Related branches

Thomas Ward (teward)
Changed in nginx (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Dmitry Shachnev (mitya57) wrote :

Sync is not (yet) possible, I've prepared a merge in lp:~mitya57/ubuntu/saucy/nginx/1.4.1.

summary: - Sync nginx 1.4.1-1 (universe) from Debian unstable (main)
+ Merge nginx 1.4.1-1 (universe) from Debian unstable (main)
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in nginx (Ubuntu):
status: New → Confirmed
Revision history for this message
CSRedRat (csredrat) wrote :

Can you made nginx default http-server or add to standard package distribution?

Revision history for this message
Thomas Ward (teward) wrote :

CSRedRat:

I'm not entirely certain that I understand what you're asking.

As for availability in the repositories, 1.4.1-1 is probably going to be merged into Saucy, and be available there once merged, and nginx is in Universe for all the other releases. The nginx team (and myself) maintain a PPA that contains 1.4.1-1 for earlier releases, but those releases I don't think would be upgraded to 1.4.1.

As for what's default, the current "default" is Apache, and that would require additional discussion amongst the server team as to whether or not to change it. I will discuss this with the server team at the next meeting.

CSRedRat (csredrat)
tags: added: upgrade-software-version
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package nginx - 1.4.1-1ubuntu1

---------------
nginx (1.4.1-1ubuntu1) saucy; urgency=low

  * Merge with Debian unstable (LP: #1177919). Remaining changes:
    - debian/conf/sites-available/default:
      + Modify default site configuration file to correct a typo
        that prevented out-of-the-box usability (LP: #1162177).
    - debian/patches/ubuntu-branding.patch:
      + Add ubuntu branding to server_tokens.
  * Refresh all patches.
 -- Dmitry Shachnev <email address hidden> Sat, 11 May 2013 14:47:53 +0400

Changed in nginx (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.