[3.3] nginx: NULL pointer dereference while writing client request body (CVE-2016-4450)
A problem was identified in nginx code responsible for saving
client request body to a temporary file. A specially crafted request
might result in worker process crash due to a NULL pointer dereference
while writing client request body to a temporary file
Affected versions:
nginx 1.3.9 - 1.11.0.
Fixed In Version:
nginx 1.11.1, nginx 1.10.1
References:
http://mailman.nginx.org/pipermail/nginx-announce/2016/000179.html
Patch for nginx 1.9.13 - 1.11.0:
http://nginx.org/download/patch.2016.write.txt
Patch for older nginx versions (1.3.9 - 1.9.12):
http://nginx.org/download/patch.2016.write2.txt
(from redmine: issue id 5676, created on 2016-06-02, closed on 2016-06-24)
- Relations:
- parent #5675 (closed)
- Changesets:
- Revision 6123c213 on 2016-06-23T14:08:43Z:
main/nginx: security fix (CVE-2016-4450). Fixes #5676