Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there a better list of fixed versions for E.G. Apache / Lighttpd (n/a No http/2 support) / Nginx?


For nginx, versions 1.16.1+ and 1.17.3+ from upstream fix at least three of the vulnerabilities (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516), however if you use a version provided by a distribution’s repositories (e.g., nginx 1.16 included with Ubuntu 18.04 LTS) you’ll need to watch for those security advisories and fixes separately which may have different version numbers due to the backporting.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: