Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package nginx for openSUSE:Factory checked 
in at 2022-10-22 14:12:45
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/nginx (Old)
 and      /work/SRC/openSUSE:Factory/.nginx.new.2275 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "nginx"

Sat Oct 22 14:12:45 2022 rev:77 rq:1030027 version:1.23.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/nginx/nginx.changes      2022-07-22 
19:20:13.220556948 +0200
+++ /work/SRC/openSUSE:Factory/.nginx.new.2275/nginx.changes    2022-10-22 
14:13:19.832772622 +0200
@@ -1,0 +2,24 @@
+Wed Oct 19 14:06:29 UTC 2022 - Michael Str??der <mich...@stroeder.com>
+
+- Updated to 1.23.2
+  * Security: processing of a specially crafted mp4 file by the
+    ngx_http_mp4_module might cause a worker process crash, worker
+    process memory disclosure, or might have potential other impact
+    (CVE-2022-41741, CVE-2022-41742).
+  * Feature: the "$proxy_protocol_tlv_..." variables.
+  * Feature: TLS session tickets encryption keys are now automatically
+    rotated when using shared memory in the "ssl_session_cache"
+    directive.
+  * Change: the logging level of the "bad record type" SSL errors has
+    been lowered from "crit" to "info".
+  * Change: now when using shared memory in the "ssl_session_cache"
+    directive the "could not allocate new session" errors are logged at
+    the "warn" level instead of "alert" and not more often than once per 
second.
+  * Bugfix: nginx/Windows could not be built with OpenSSL 3.0.x.
+  * Bugfix: in logging of the PROXY protocol errors.
+  * Workaround: shared memory from the "ssl_session_cache" directive was
+    spent on sessions using TLS session tickets when using TLSv1.3 with 
OpenSSL.
+  * Workaround: timeout specified with the "ssl_session_timeout"
+    directive did not work when using TLSv1.3 with OpenSSL or BoringSSL.
+
+-------------------------------------------------------------------

Old:
----
  nginx-1.23.1.tar.gz
  nginx-1.23.1.tar.gz.asc

New:
----
  nginx-1.23.2.tar.gz
  nginx-1.23.2.tar.gz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ nginx.spec ++++++
--- /var/tmp/diff_new_pack.0U3AN5/_old  2022-10-22 14:13:20.456774101 +0200
+++ /var/tmp/diff_new_pack.0U3AN5/_new  2022-10-22 14:13:20.468774129 +0200
@@ -23,7 +23,7 @@
 %bcond_with    ngx_google_perftools
 #
 Name:           nginx
-Version:        1.23.1
+Version:        1.23.2
 Release:        0
 Summary:        A HTTP server and IMAP/POP3 proxy server
 License:        BSD-2-Clause

++++++ nginx-1.23.1.tar.gz -> nginx-1.23.2.tar.gz ++++++
++++ 1698 lines of diff (skipped)

Reply via email to