ELA-247-1 nginx security update

HTTP request smuggling

2020-07-20
Packagenginx
Version1.6.2-5+deb8u7
Related CVEs CVE-2019-20372 CVE-2020-11724


Two HTTP request smuggling issues were discovered in nginx, a high-performance web and reverse proxy server, as well as in its ngx_lua plugin.



For Debian 8 jessie, these problems have been fixed in version 1.6.2-5+deb8u7.

We recommend that you upgrade your nginx packages.

Further information about Extended LTS security advisories can be found at: debian Extended Long term support