Format: 1.8 Date: Wed, 14 Aug 2019 14:48:49 -0400 Source: nginx Binary: nginx nginx-doc nginx-common nginx-core nginx-core-dbg nginx-full nginx-full-dbg nginx-light nginx-light-dbg nginx-extras nginx-extras-dbg Architecture: all amd64 amd64_translations Version: 1.10.3-0ubuntu0.16.04.4 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: nginx - small, powerful, scalable web/proxy server nginx-common - small, powerful, scalable web/proxy server - common files nginx-core - nginx web/proxy server (core version) nginx-core-dbg - nginx web/proxy server (core version) - debugging symbols nginx-doc - small, powerful, scalable web/proxy server - documentation nginx-extras - nginx web/proxy server (extended version) nginx-extras-dbg - nginx web/proxy server (extended version) - debugging symbols nginx-full - nginx web/proxy server (standard version) nginx-full-dbg - nginx web/proxy server (standard version) - debugging symbols nginx-light - nginx web/proxy server (basic version) nginx-light-dbg - nginx web/proxy server (basic version) - debugging symbols Changes: nginx (1.10.3-0ubuntu0.16.04.4) xenial-security; urgency=medium . * SECURITY UPDATE: HTTP/2 Data Dribble issue - debian/patches/CVE-2019-9511.patch: limited number of DATA frames in src/http/v2/ngx_http_v2.c, src/http/v2/ngx_http_v2.h, src/http/v2/ngx_http_v2_filter_module.c. - CVE-2019-9511 * SECURITY UPDATE: HTTP/2 Resource Loop / Priority Shuffling issue - debian/patches/CVE-2019-9513.patch: limited number of PRIORITY frames in src/http/v2/ngx_http_v2.c, src/http/v2/ngx_http_v2.h. - CVE-2019-9513 * SECURITY UPDATE: HTTP/2 0-Length Headers Leak issue - debian/patches/CVE-2019-9516.patch: reject zero length headers with PROTOCOL_ERROR in src/http/v2/ngx_http_v2.c. - CVE-2019-9516 Checksums-Sha1: 78e43cf64f28771a4face513f70f194e494664cd 26928 nginx-common_1.10.3-0ubuntu0.16.04.4_all.deb f8d6449cd428792fe9de5f6cbccd30da0ceb3152 3335774 nginx-core-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 816e7689952382810f648bb005e0690de4adfc8a 1350 nginx-core-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb a5894246f2231f6d080c5f1364a7ea92909f20f2 429064 nginx-core_1.10.3-0ubuntu0.16.04.4_amd64.deb c17a1e372d53d9d7c29eed40ba36dad338b0d6d5 16990 nginx-doc_1.10.3-0ubuntu0.16.04.4_all.deb 30e256f4cc7835005c6df63d876f0322966c86c4 5882730 nginx-extras-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 23eb9007ad5d1ee7821de6cb6ce38cbc1930af34 1432 nginx-extras-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb b335b04bc74b5fdac8216cde98368d019ec4ef63 630510 nginx-extras_1.10.3-0ubuntu0.16.04.4_amd64.deb 73dc2f22a8eeb85b274cdd1a4b4d3075c590533f 3788428 nginx-full-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 6850c5a2a427039be4b8370af9c35c002c48b6f9 1346 nginx-full-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 42281e976003c3c0ad8513a9b202cf3651f07bf1 453524 nginx-full_1.10.3-0ubuntu0.16.04.4_amd64.deb bd6924666a8751c29c5e055d0f8786456c2f251c 2408852 nginx-light-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 3bf233a90e00731b94c81689a8c49992dc67ab58 1148 nginx-light-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 4c9f5763eed06ad91a6e87aeee43dc5b0b94c0de 315146 nginx-light_1.10.3-0ubuntu0.16.04.4_amd64.deb 2fc333bbfbbba049eb60fafff95479ceff4a94e9 3498 nginx_1.10.3-0ubuntu0.16.04.4_all.deb 579aa00a3a132f53d0cae6671ae665d90aa43edc 905 nginx_1.10.3-0ubuntu0.16.04.4_amd64_translations.tar.gz Checksums-Sha256: ed1f8d6f84b9180e5ddc6651fb32f3fea15b15b0a1a70f14fff3ad7f313f220f 26928 nginx-common_1.10.3-0ubuntu0.16.04.4_all.deb 8f9cd42521e0c9603f92e8fe6de67d83e5bba994412b2c096aad205d4d69f99c 3335774 nginx-core-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb e4cb2dcc6699f1d517d6b62d61982cf76bf2c9e4885a4c6d69c6fa849180ff65 1350 nginx-core-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 2d7f25ddf9690b0ed3d8a30e382a2912107228048b95bf045147a564ad67af26 429064 nginx-core_1.10.3-0ubuntu0.16.04.4_amd64.deb 0240c3802d375f632a43266535609f4265260e22471a1a3c33607da65b016363 16990 nginx-doc_1.10.3-0ubuntu0.16.04.4_all.deb 2151da1cbde6192ea11e5a4ba9dde2d089afc38972337d2c41f9782f81d9fbaa 5882730 nginx-extras-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb c5d5cd3f35d9c345dd007e199c59bc495e0eac99bc7122b9cd9bff133f39b819 1432 nginx-extras-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 4fbb9815dec8805b92cd0123280c06c92da81e4eb0a81bfb279d3c44b97975ad 630510 nginx-extras_1.10.3-0ubuntu0.16.04.4_amd64.deb d22fd7bc8550e53c91c843ceba77d2f89378209752faa761224afbec3b75235a 3788428 nginx-full-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb cad4a8e0ccfc11767c61a514a3c1ac2db1733bfd13667243d31e012183647392 1346 nginx-full-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 723887cb00bf56141805d33f2d4134575bf19397f4db352e4eedc72706597bf1 453524 nginx-full_1.10.3-0ubuntu0.16.04.4_amd64.deb c650be2933b222c1598025126fb49e95ae472c1be6c99d7d152729253f62d27b 2408852 nginx-light-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 0da26bf397c72c369a30bf15e0a0b8ac04c88f3327ad040470860ec512731a6d 1148 nginx-light-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 471b25602d7f9aa49502599caba751e070d61f52deda1141085d1a22cc62607c 315146 nginx-light_1.10.3-0ubuntu0.16.04.4_amd64.deb 9ac8b08428ce17825dda6fc907e4492f134bfa65953e580b988749892f0cbb09 3498 nginx_1.10.3-0ubuntu0.16.04.4_all.deb c218f36a75ea27aa1382d3ff98901374d55977c81547c703b92d0768cffd39f0 905 nginx_1.10.3-0ubuntu0.16.04.4_amd64_translations.tar.gz Files: 7369c048599005576d519c8d65ae4db9 26928 httpd optional nginx-common_1.10.3-0ubuntu0.16.04.4_all.deb 827670ea94efba4abb9086bcb724a888 3335774 debug extra nginx-core-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 5fefaf6c0de0171aadeda6ce71e3e2d2 1350 httpd extra nginx-core-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb f846b5320a9819377a29f570c27f667e 429064 httpd optional nginx-core_1.10.3-0ubuntu0.16.04.4_amd64.deb d19def3c38c787b095148f6574103805 16990 doc optional nginx-doc_1.10.3-0ubuntu0.16.04.4_all.deb acc97164324697d8b8e698f4d938b7cc 5882730 debug extra nginx-extras-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 1d86f671d16704a05ed5339cb11a57d2 1432 httpd extra nginx-extras-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb e98dad518f45a1d53fab8376c6db6236 630510 httpd extra nginx-extras_1.10.3-0ubuntu0.16.04.4_amd64.deb 28952b4919a67650c3f37d689505afcd 3788428 debug extra nginx-full-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 1c67fba9fc50e6c6f34a674ae5e9031b 1346 httpd extra nginx-full-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 79bf5953e0edb63d96a5e9ee210853d9 453524 httpd optional nginx-full_1.10.3-0ubuntu0.16.04.4_amd64.deb 5f23b54d31804eab446daa9c46ffeca9 2408852 debug extra nginx-light-dbg_1.10.3-0ubuntu0.16.04.4_amd64.deb 044aebc982233fd4e71735b3dc0f137d 1148 httpd extra nginx-light-dbgsym_1.10.3-0ubuntu0.16.04.4_amd64.ddeb 0c4980c4a050f092e10dc98989337d28 315146 httpd extra nginx-light_1.10.3-0ubuntu0.16.04.4_amd64.deb 2c21cdf43eb5f2e07a4ba2b90f6bc99e 3498 httpd optional nginx_1.10.3-0ubuntu0.16.04.4_all.deb 436879cc855d981351594bed6fa1cee3 905 raw-translations - nginx_1.10.3-0ubuntu0.16.04.4_amd64_translations.tar.gz Original-Maintainer: Kartik Mistry