[SECURITY] Fedora 40 Update: nginx-mod-vts-0.2.3-3.fc40

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-016ed44ddc
2025-02-15 02:22:06.812098+00:00
--------------------------------------------------------------------------------

Name        : nginx-mod-vts
Product     : Fedora 40
Version     : 0.2.3
Release     : 3.fc40
URL         : https://github.com/vozlt/nginx-module-vts
Summary     : Nginx virtual host traffic status module
Description :
Nginx virtual host traffic status module.

--------------------------------------------------------------------------------
Update Information:

Changes with nginx 1.26.3                                        05 Feb 2025
*) Security: insufficient check in virtual servers handling with TLSv1.3
   SNI allowed to reuse SSL sessions in a different virtual server, to
   bypass client SSL certificates verification (CVE-2025-23419).
*) Bugfix: in the ngx_http_mp4_module.
   Thanks to Nils Bars.
*) Workaround: "gzip filter failed to use preallocated memory" alerts
   appeared in logs when using zlib-ng.
*) Bugfix: nginx could not build libatomic library using the library
   sources if the --with-libatomic=DIR option was used.
*) Bugfix: nginx now ignores QUIC version negotiation packets from
   clients.
*) Bugfix: nginx could not be built on Solaris 10 and earlier with the
   ngx_http_v3_module.
*) Bugfixes in HTTP/3.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb  6 2025 Felix Kaechele <felix@xxxxxxxxxxx> - 0.2.3-3
- Rebuild for nginx 1.26.3
* Fri Jan 17 2025 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Jan  2 2025 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 0.2.3-1
- Update to 0.2.3 rhbz#2335121
* Mon Sep  2 2024 Miroslav Suchý <msuchy@xxxxxxxxxx> - 0.2.2-11
- convert license to SPDX
* Mon Aug 26 2024 Felix Kaechele <felix@xxxxxxxxxxx> - 0.2.2-10
- Rebuild for nginx 1.26.2... again.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2277663 - please switch to using systemd-sysusers to create the nginx user
        https://bugzilla.redhat.com/show_bug.cgi?id=2277663
  [ 2 ] Bug #2344197 - CVE-2025-23419 nginx: TLS Session Resumption Vulnerability [fedora-40]
        https://bugzilla.redhat.com/show_bug.cgi?id=2344197
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-016ed44ddc' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- package-announce@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to package-announce-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

[Index of Archives]     [Fedora Users]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [Yosemite Photos]     [KDE Users]

  Powered by Linux