Is nginx still vulnerable to CVE-2009-4487 ?

2022-02-13 Thread Hritik Vijay
Hello The advisories page (https://nginx.org/en/security_advisories.html) for nginx mentions the following: An error log data are not sanitized Severity: none CVE-2009-4487 Not vulnerable: none Vulnerable: all Was this vulnerability ever fixed ? If so, can

Nginx advisories with not vulnerable versions inside the vulnerable range

2021-12-28 Thread Hritik Vijay
Hello I'm trying to parse the advisories page present at https://nginx.org/en/security_advisories.html. So far, I've understood the even-odd minor versioning scheme for branches (thanks to Maxim at https://marc.info/?l=nginx&m=163174223924231&w=2). There still exists some advisories that are hard

Confusing version ranges in security advisories

2021-09-15 Thread Hritik Vijay
o define the plus operator as a footnote/topnote on the advisories page for future. -- Regards Hritik Vijay ___ nginx mailing list nginx@nginx.org http://mailman.nginx.org/mailman/listinfo/nginx