Format: 1.8 Date: Tue, 18 Oct 2016 11:12:58 +0200 Source: nginx Binary: nginx nginx-doc nginx-common nginx-core nginx-core-dbg nginx-full nginx-full-dbg nginx-light nginx-light-dbg nginx-extras nginx-extras-dbg nginx-naxsi nginx-naxsi-dbg nginx-naxsi-ui Architecture: amd64 amd64_translations Version: 1.4.6-1ubuntu3.6 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: nginx - small, powerful, scalable web/proxy server nginx-common - small, powerful, scalable web/proxy server - common files nginx-core - nginx web/proxy server (core version) nginx-core-dbg - nginx web/proxy server (core version) - debugging symbols nginx-doc - small, powerful, scalable web/proxy server - documentation nginx-extras - nginx web/proxy server (extended version) nginx-extras-dbg - nginx web/proxy server (extended version) - debugging symbols nginx-full - nginx web/proxy server (standard version) nginx-full-dbg - nginx web/proxy server (standard version) - debugging symbols nginx-light - nginx web/proxy server (basic version) nginx-light-dbg - nginx web/proxy server (basic version) - debugging symbols nginx-naxsi - nginx web/proxy server (version with naxsi) nginx-naxsi-dbg - nginx web/proxy server (version with naxsi) - debugging symbols nginx-naxsi-ui - nginx web/proxy server - naxsi configuration front-end Changes: nginx (1.4.6-1ubuntu3.6) trusty-security; urgency=medium . [ Christos Trochalakis ] * debian/nginx-common.postinst: + Secure log file handling (owner & permissions) against privilege escalation attacks. /var/log/nginx is now owned by root:adm. Thanks Dawid Golunski (http://legalhackers.com) for the report. Changing /var/log/nginx permissions effectively reopens #701112, since log files can be world-readable. This is a trade-off until a better log opening solution is implemented upstream (trac:376). Checksums-Sha1: 68b64cfa369bd937cec769b707aaf432431f2533 325078 nginx-core_1.4.6-1ubuntu3.6_amd64.deb 862d692a7f46d712a186c2fa12d6bf25d81abc30 2691152 nginx-core-dbg_1.4.6-1ubuntu3.6_amd64.deb 1427a385d79dae4b577e9664fa78746e2c11144c 343530 nginx-full_1.4.6-1ubuntu3.6_amd64.deb eebf1ee321f213d18664778757f51d9323f7fd63 3104760 nginx-full-dbg_1.4.6-1ubuntu3.6_amd64.deb 2fab7621f153a2b7c31b7065892849e803aa0664 252388 nginx-light_1.4.6-1ubuntu3.6_amd64.deb 6830e1172bd5c601aed65a6b9992e83aa84559b3 2107194 nginx-light-dbg_1.4.6-1ubuntu3.6_amd64.deb 05b114cadbe7f8633bd34f1105d1eca22ef4a363 495226 nginx-extras_1.4.6-1ubuntu3.6_amd64.deb a93b979136dc981a86eaa7592e8901792973cba7 4804994 nginx-extras-dbg_1.4.6-1ubuntu3.6_amd64.deb 5729717f2438cc018d5e6867923a128e4d3ae482 288968 nginx-naxsi_1.4.6-1ubuntu3.6_amd64.deb 19081d439cb1c921b5c898ef65b7ec6b42ed27f8 2247386 nginx-naxsi-dbg_1.4.6-1ubuntu3.6_amd64.deb 1a641f5abd87eb8e0e5429bca0ef3d531e2646f6 1330 nginx-core-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb f7a6169f9dc8e39028f8991c33757c93efd45b54 1330 nginx-full-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 7123bc046ddf86f6448aa806a144a0cef0971738 1134 nginx-light-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 6c008825a8b8c32dd413151dd1fc57513a70b7ee 1420 nginx-extras-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb c376074d5eff249fa4db028befb0b213b85430c7 1206 nginx-naxsi-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb c18bc9643711a8210a74c26c9042bb3a17156788 4571 nginx_1.4.6-1ubuntu3.6_amd64_translations.tar.gz Checksums-Sha256: 90f1b339b8b805ea16328cfa9fc608990ffa5df319eec0360b6360888115bdef 325078 nginx-core_1.4.6-1ubuntu3.6_amd64.deb 2c923222e6c24d402c8e5c98d16d016ef51e57ea2312887c8f5b7318380f11a9 2691152 nginx-core-dbg_1.4.6-1ubuntu3.6_amd64.deb 05c2c477b401c7282f81777a9a73612b7fb703438695b79d7fb65f5da7ec06e2 343530 nginx-full_1.4.6-1ubuntu3.6_amd64.deb dfcab086c27c577ae36513489fd1a27ecb79127f60a16e456456919cfd095757 3104760 nginx-full-dbg_1.4.6-1ubuntu3.6_amd64.deb 6326f14b935c6d679906b9342e6850c9fd69a7d4f72951a85351ecd07ff4b0b9 252388 nginx-light_1.4.6-1ubuntu3.6_amd64.deb dbbb999e4fef0addf02cf65a1cd005ec2b2dfe237ed99ffe88796320927bbf85 2107194 nginx-light-dbg_1.4.6-1ubuntu3.6_amd64.deb 58f27de10f7af7316d78d46b895cfd4ccdc5f5a628dd66e2266bb7678dbcd962 495226 nginx-extras_1.4.6-1ubuntu3.6_amd64.deb f59be85b64e8d618f8bcc36d6a233bb1281200b1de94b8663abf3e7a3a2c8d61 4804994 nginx-extras-dbg_1.4.6-1ubuntu3.6_amd64.deb 8bbea53d1c73a649bf295abbff07df3897cfe82490296dc3de06430bbcb56a31 288968 nginx-naxsi_1.4.6-1ubuntu3.6_amd64.deb 721628370b3ec6ee9dcd347c8f40b8bcae01e0d7a7f4d0fea2a5022177bfcc47 2247386 nginx-naxsi-dbg_1.4.6-1ubuntu3.6_amd64.deb 2fbb6796d1a106f3dcf6f5983ae7faccf7ec57ed9f82cee651baca0bc2dfd129 1330 nginx-core-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 306fd87fb30e69beed1bdf5c6a96689895a01f2332594e6179dec67be8f732b9 1330 nginx-full-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 0ef225d0eac36c2c2dc0565c0c790ceaeeb19827d66aa3f0d07d25785a270ca4 1134 nginx-light-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb bdd20ec0ff3ddbccfe7e2780018c58fe1a564f63b6918eda0ca58c87db065165 1420 nginx-extras-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 1dbc6b15402643f5ff61cc3799abe8401f52d214e8917ef976f1c449d9899219 1206 nginx-naxsi-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 601b78e2037ab4738ac3b603bbf7c9baa4ab7f899c63b32e1e5f4762ca365c90 4571 nginx_1.4.6-1ubuntu3.6_amd64_translations.tar.gz Files: 51812953bc985f4923e7a4aac8c176b1 325078 httpd optional nginx-core_1.4.6-1ubuntu3.6_amd64.deb 39c9bdfd03e887200ae145abb0bc3cf4 2691152 debug extra nginx-core-dbg_1.4.6-1ubuntu3.6_amd64.deb c59ccfce3f250a1ef4794953ed930dce 343530 httpd optional nginx-full_1.4.6-1ubuntu3.6_amd64.deb 662ba05738be447bcc4a820afa5621e9 3104760 debug extra nginx-full-dbg_1.4.6-1ubuntu3.6_amd64.deb f0f25a5ebe8118beb2dd72154718a668 252388 httpd extra nginx-light_1.4.6-1ubuntu3.6_amd64.deb 1ded5244740a1e71a014c7956af086e9 2107194 debug extra nginx-light-dbg_1.4.6-1ubuntu3.6_amd64.deb dd5674c0a5de3f55a62b85c7e807e2c4 495226 httpd extra nginx-extras_1.4.6-1ubuntu3.6_amd64.deb 59bee39b3bdf7b3705fc79259fa38c63 4804994 debug extra nginx-extras-dbg_1.4.6-1ubuntu3.6_amd64.deb 88bed83ac4b93285610dc94fab2c297c 288968 httpd extra nginx-naxsi_1.4.6-1ubuntu3.6_amd64.deb f6ba708313945b9696aa87abcdc7504e 2247386 debug extra nginx-naxsi-dbg_1.4.6-1ubuntu3.6_amd64.deb 11c61a7f9e15548f238c6a38feea63e0 1330 httpd extra nginx-core-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb ff04c698d257e6796fe953894f2061de 1330 httpd extra nginx-full-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 8d7fef5e3a6f5dbd42c982efb7cfb38c 1134 httpd extra nginx-light-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb fcdb335b569cccc207425ab979c075e0 1420 httpd extra nginx-extras-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb 03b2712835600528323930fdfd20305b 1206 httpd extra nginx-naxsi-dbgsym_1.4.6-1ubuntu3.6_amd64.ddeb dad28a72604e305757142eb9af9c9cdf 4571 raw-translations - nginx_1.4.6-1ubuntu3.6_amd64_translations.tar.gz Original-Maintainer: Kartik Mistry