Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-16 Thread Luciano Bello
On Friday 16 March 2012, Kartik Mistry wrote: Do you want me to upload it directly to stable or want to send email to security with debdiff etc? Yes, please. Thank you :) /luciano signature.asc Description: This is a digitally signed message part.

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-16 Thread Kartik Mistry
On Fri, Mar 16, 2012 at 7:35 PM, Luciano Bello luci...@debian.org wrote: On Friday 16 March 2012, Kartik Mistry wrote: Do you want me to upload it directly to stable or want to send email to security with debdiff etc? Yes, please. Which one? :) -- Kartik Mistry | IRC: kart_ {0x1f1f,

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-16 Thread Luciano Bello
On Friday 16 March 2012, Kartik Mistry wrote: Which one? :) Hehhe... please, upload. -l signature.asc Description: This is a digitally signed message part.

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-16 Thread Kartik Mistry
On Fri, Mar 16, 2012 at 8:30 PM, Luciano Bello luci...@debian.org wrote: On Friday 16 March 2012, Kartik Mistry wrote: Which one? :) Hehhe... please, upload. Done. Thanks! -- Kartik Mistry | IRC: kart_ {0x1f1f, kartikm}.wordpress.com -- To UNSUBSCRIBE, email to

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Luciano Bello
Package: nginx Severity: grave Tags: security patch The following vulnerability had been reported against nginx: http://seclists.org/oss-sec/2012/q1/644 The patch can be found in the report. Please use CVE-2012-1180 for this issue. Can you check if the stable version is affected? Cheers,

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Cyril Lavier
On 03/15/2012 08:54 PM, Luciano Bello wrote: Package: nginx Severity: grave Tags: security patch The following vulnerability had been reported against nginx: http://seclists.org/oss-sec/2012/q1/644 The patch can be found in the report. Please use CVE-2012-1180 for this issue. Can you check

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Cyril Lavier
On 03/15/2012 09:28 PM, Luciano Bello wrote: On Thursday 15 March 2012, Cyril Lavier wrote: The 1.1.17 will be uploaded tomorrow, we already done the needed test for the upload (build and functionality). Great! Can you check if stable is affected? The bug looks quite important. Do you think

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Luciano Bello
On Thursday 15 March 2012, Cyril Lavier wrote: The 1.1.17 will be uploaded tomorrow, we already done the needed test for the upload (build and functionality). Great! Can you check if stable is affected? The bug looks quite important. Do you think that stable should be updated by a DSA?

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Cyril Lavier
On 03/15/2012 09:34 PM, Cyril Lavier wrote: On 03/15/2012 09:28 PM, Luciano Bello wrote: On Thursday 15 March 2012, Cyril Lavier wrote: The 1.1.17 will be uploaded tomorrow, we already done the needed test for the upload (build and functionality). Great! Can you check if stable is affected?

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Luciano Bello
On Thursday 15 March 2012, Cyril Lavier wrote: For old-stable, I don't have time tonight, so if anybody is willing to do it, don't hesitate :). Security does not support old-stable since Febrary. Thanks a lot for your work! -l -- To UNSUBSCRIBE, email to

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Kartik Mistry
On Fri, Mar 16, 2012 at 2:49 AM, Luciano Bello luci...@debian.org wrote: On Thursday 15 March 2012, Cyril Lavier wrote: For old-stable, I don't have time tonight, so if anybody is willing to do it, don't hesitate :). Do you want me to upload it directly to stable or want to send email to