1. 修復的CVE信息
CVE-2021-23017
F5 NGINX Controller是美國F5公司的一款用于NGINX的集中式監視和管理平臺。該平臺支持使用可視化界面管理多個NGINX實例。F5 NGINX Controller存在安全漏洞,該漏洞允許攻擊者從DNS服務器偽造UDP數據包造成1-byte的內存覆蓋,導致工作進程崩潰或潛在的其他影響。
2. 受影響的軟件包
銀河麒麟桌面操作系統V10 SP1
libnginx-mod-http-auth-pam
libnginx-mod-http-cache-purge
libnginx-mod-http-dav-ext
libnginx-mod-http-echo
libnginx-mod-http-fancyindex
libnginx-mod-http-geoip
libnginx-mod-http-geoip2
libnginx-mod-http-headers-more-filter
libnginx-mod-http-image-filter
libnginx-mod-http-lua
libnginx-mod-http-ndk
libnginx-mod-http-perl
libnginx-mod-http-subs-filter
libnginx-mod-http-uploadprogress
libnginx-mod-http-upstream-fair
libnginx-mod-http-xslt-filter
libnginx-mod-mail
libnginx-mod-nchan
libnginx-mod-rtmp
libnginx-mod-stream
nginx
nginx-common
nginx-core
nginx-doc
nginx-extras
nginx-full
nginx-light
3. 影響的操作系統
銀河麒麟桌面操作系統V10 SP1
4. 修復版本
軟件包:nginx
1.18.0-0kylin1.2(V10 SP1)
5. 修復方法
4.0.2桌面版本:http://archive.kylinos.cn/kylin/KYLIN-ALL 4.0.2-desktop main restricted universe multiverse
6. 軟件包下載地址
銀河麒麟桌面操作系統V10 SP1
X86下載地址
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/n/nginx/nginx-extras_1.18.0-0kylin1.2_amd64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/n/nginx/nginx-core_1.18.0-0kylin1.2_amd64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/n/nginx/nginx-common_1.18.0-0kylin1.2_all.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/n/nginx/nginx-full_1.18.0-0kylin1.2_amd64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/n/nginx/nginx_1.18.0-0kylin1.2_all.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/n/nginx/nginx-doc_1.18.0-0kylin1.2_all.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/n/nginx/nginx-light_1.18.0-0kylin1.2_amd64.deb