Activity log for bug #1370478

Date Who What changed Old value New value Message
2014-09-17 12:06:55 Thomas Ward bug added bug
2014-09-17 12:07:52 Thomas Ward nominated for series Ubuntu Precise
2014-09-17 12:07:52 Thomas Ward nominated for series Ubuntu Utopic
2014-09-17 12:07:52 Thomas Ward nominated for series Ubuntu Lucid
2014-09-17 12:07:52 Thomas Ward nominated for series Ubuntu Trusty
2014-09-17 12:08:37 Thomas Ward description A security vulnerability was found in the nginx package. ------ This is the email that went out in the nginx security advisories list regarding this vulnerability: Hello! A problem with SSL session cache in nginx was identified by Antoine Delignat-Lavaud. It was possible to reuse cached SSL sessions in unrelated contexts, allowing virtual host confusion attacks in some configurations by an attacker in a privileged network position (CVE-2014-3616). The problem affects nginx 0.5.6 - 1.7.4 if the same shared ssl_session_cache and/or ssl_session_ticket_key are used for multiple server{} blocks. The problem is fixed in nginx 1.7.5, 1.6.2. Further details can be found in the paper by Antoine Delignat-Lavaud et al., available at http://bh.ht.vc/vhost_confusion.pdf. ------ This is CVE-2014-3616. ------ This has been fixed upstream in nginx. This has also been fixed in Debian. ------ The Debian bug for this is: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761940 A security vulnerability was found in the nginx package. All versions in Lucid, Precise, Trusty, and Utopic are affected. ------ This is the email that went out in the nginx security advisories list regarding this vulnerability: Hello! A problem with SSL session cache in nginx was identified by Antoine Delignat-Lavaud. It was possible to reuse cached SSL sessions in unrelated contexts, allowing virtual host confusion attacks in some configurations by an attacker in a privileged network position (CVE-2014-3616). The problem affects nginx 0.5.6 - 1.7.4 if the same shared ssl_session_cache and/or ssl_session_ticket_key are used for multiple server{} blocks. The problem is fixed in nginx 1.7.5, 1.6.2. Further details can be found in the paper by Antoine Delignat-Lavaud et al., available at http://bh.ht.vc/vhost_confusion.pdf. ------ This is CVE-2014-3616. ------ This has been fixed upstream in nginx. This has also been fixed in Debian. ------ The Debian bug for this is: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761940
2014-09-17 12:09:13 Thomas Ward bug watch added http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761940
2014-09-17 12:09:13 Thomas Ward bug task added nginx (Debian)
2014-09-17 12:10:23 Thomas Ward summary [CVE-2014-3616] "reuse cached SSL sessions in unrelated contexts" [CVE-2014-3616] "possible to reuse cached SSL sessions in unrelated contexts"
2014-09-17 12:19:12 Marc Deslauriers bug task added nginx (Ubuntu Lucid)
2014-09-17 12:19:21 Marc Deslauriers bug task added nginx (Ubuntu Precise)
2014-09-17 12:19:31 Marc Deslauriers bug task added nginx (Ubuntu Trusty)
2014-09-17 12:19:37 Marc Deslauriers bug task added nginx (Ubuntu Utopic)
2014-09-17 12:21:56 Thomas Ward cve linked 2014-3616
2014-09-17 12:23:32 Thomas Ward nginx (Ubuntu): status New Confirmed
2014-09-17 12:59:55 Marc Deslauriers nginx (Ubuntu Trusty): status New Confirmed
2014-09-17 13:00:00 Marc Deslauriers nginx (Ubuntu Lucid): status New Won't Fix
2014-09-17 13:00:03 Marc Deslauriers nginx (Ubuntu Precise): status New Confirmed
2014-09-17 13:00:08 Marc Deslauriers nginx (Ubuntu Trusty): assignee Marc Deslauriers (mdeslaur)
2014-09-17 14:35:23 Bug Watch Updater nginx (Debian): status Unknown Fix Released
2014-09-22 16:19:42 Launchpad Janitor nginx (Ubuntu Trusty): status Confirmed Fix Released
2014-09-22 17:09:27 Launchpad Janitor branch linked lp:ubuntu/trusty-security/nginx
2014-09-23 14:41:56 Marc Deslauriers nginx (Ubuntu Utopic): status Confirmed Fix Released
2015-01-06 18:22:05 Launchpad Janitor nginx (Ubuntu Precise): status Confirmed Fix Released
2015-01-06 18:34:33 Launchpad Janitor branch linked lp:ubuntu/precise-security/nginx