全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
楼主: pigicoffee

nginx记得打补丁

[复制链接]
发表于 2009-10-17 18:33:56 | 显示全部楼层
找到了,漏洞描述:

http://www.kb.cert.org/vuls/id/180065

Vulnerability Note VU#180065
Nginx ngx_http_parse_complex_uri() buffer underflow vulnerability
Overview
A vulnerability in the nginx web server may allow remote attackers to execute arbitrary code on an affected system.
I. Description
nginx is an HTTP server and mail proxy server that is available for a number of different platforms. A buffer underflow vulnerability exists in the ngx_http_parse_complex_uri() function when handling specially crafted URIs. Exploitation of this vulnerability would cause the nginx server to write data contained in the URI to heap memory before the allocated buffer.
II. Impact
As with a number of other web servers, nginx is designed to operate with a single privileged master process and multiple unprivileged worker processes handling specific requests. A remote, unauthenticated attacker may be able to execute arbitrary code in the context of the worker process or cause the worker process to crash, resulting in a denial of service.
III. Solution
Upgrade or apply a patch
Updated versions of the nginx package have been released to address this issue. Users should consult the Systems Affected section of this document for information about specific vendors.
发表于 2009-10-17 18:42:56 | 显示全部楼层
跟着freebsd的脚步,我也升级好了,nginx/0.7.62
发表于 2009-10-17 18:46:07 | 显示全部楼层
你用的不是稳定版的吗?
干嘛还升级这么快?
发表于 2009-10-17 18:46:46 | 显示全部楼层
原帖由 cpuer 于 2009-10-17 18:42 发表
跟着freebsd的脚步,我也升级好了,nginx/0.7.62


C大,我这0.7.61升级0.7.62简单吗?有没有时间帮我升级一下,呵呵
发表于 2009-10-17 18:54:34 | 显示全部楼层
原帖由 junhan 于 2009-10-17 18:46 发表


C大,我这0.7.61升级0.7.62简单吗?有没有时间帮我升级一下,呵呵


刚写了个流程供大家分享,http://www.hostloc.com/thread-4871-1-1.html  可以看看,很简单。
发表于 2009-10-17 19:15:35 | 显示全部楼层

回复 12# 的帖子

我准备全更新,其他的php,mysql什么的,全更新,反正freebsd有个很NB的更新机制。
发表于 2009-10-17 19:32:48 | 显示全部楼层
呵呵,你的更新源没有更新的话,你还是得手动更新.
发表于 2009-10-17 20:25:18 | 显示全部楼层
原帖由 freebsd 于 2009-10-17 19:15 发表
我准备全更新,其他的php,mysql什么的,全更新,反正freebsd有个很NB的更新机制。


ports ?
发表于 2009-10-17 20:26:03 | 显示全部楼层
原帖由 cnx 于 2009-10-17 18:46 发表
你用的不是稳定版的吗?
干嘛还升级这么快?


0.7.61 有安全隐患, 而且0.7.62已经是最新的稳定版了,所以就升级到0.7.62了
发表于 2009-10-17 20:42:45 | 显示全部楼层
...C大 那篇说明档 写得好笼统啊 你要有空 找找 漏洞利用实例吧 呵呵
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-5-5 19:32 , Processed in 0.099598 second(s), 8 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表