CVE-2014-3616
nginx - security update
EPSS 5.7%
描述
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
如何修補 CVE-2014-3616
要修補 CVE-2014-3616,請將受影響套件升級到下列已修補版本。
- Debian/nginx—升級至 1.6.2-1 或更新版本
- Debian/nginx—升級至 0.7.67-3+squeeze4 或更新版本
- Debian/nginx—升級至 1.2.1-2.2+wheezy3 或更新版本
CVE-2014-3616 正在被利用嗎?
中等 — EPSS 為 5.7%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.6.2-1
- from 0, < 0.7.67-3+squeeze4
- from 0, < 1.2.1-2.2+wheezy3