summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMaxim Dounin <mdounin@mdounin.ru>2013-11-19 15:25:24 +0400
committerMaxim Dounin <mdounin@mdounin.ru>2013-11-19 15:25:24 +0400
commit37c4ed61ef7d8c4562053ee3bbb4aa189a616ef8 (patch)
tree9e511be99cf045bee65944fb17b6dec130738723
parent822a148df534fb30000f867d764d31e527e4ae4f (diff)
downloadnginx-37c4ed61ef7d8c4562053ee3bbb4aa189a616ef8.tar.gz
nginx-1.4.4-RELEASErelease-1.4.4
-rw-r--r--docs/xml/nginx/changes.xml20
1 files changed, 20 insertions, 0 deletions
diff --git a/docs/xml/nginx/changes.xml b/docs/xml/nginx/changes.xml
index f0e6559e1..ed5f6221e 100644
--- a/docs/xml/nginx/changes.xml
+++ b/docs/xml/nginx/changes.xml
@@ -5,6 +5,26 @@
<change_log title="nginx">
+<changes ver="1.4.4" date="19.11.2013">
+
+<change type="security">
+<para lang="ru">
+символ, следующий за незакодированным пробелом в строке запроса,
+обрабатывался неправильно (CVE-2013-4547);
+ошибка появилась в 0.8.41.<br/>
+Спасибо Ivan Fratric из Google Security Team.
+</para>
+<para lang="en">
+a character following an unescaped space in a request line
+was handled incorrectly (CVE-2013-4547);
+the bug had appeared in 0.8.41.<br/>
+Thanks to Ivan Fratric of the Google Security Team.
+</para>
+</change>
+
+</changes>
+
+
<changes ver="1.4.3" date="08.10.2013">
<change type="bugfix">