Bugtraq mailing list archives

RE: Nginx 0.8.35 Space Character Remote Source Disclosure


From: <reply-to-list () mailinator com>
Date: Mon, 31 May 2010 20:02:05 -0400

Looks like this affected Windows only, and was fixed a while ago.

Changes with nginx 0.7.65                                        01 Feb 2010

    *) Security: now nginx/Windows ignores trailing spaces in URI.
       Thanks to Dan Crowley, Core Security Technologies. 

-----Original Message-----
From: abc12345 () hushmail com [mailto:abc12345 () hushmail com] 
Sent: Monday, May 31, 2010 11:00 AM
To: bugtraq () securityfocus com
Subject: Re: Nginx 0.8.35 Space Character Remote Source Disclosure

what about the stable branch? Versions 0.7.65 and earlier?


Current thread: