nginx: Information disclosure An SSL session fixation vulnerability in nginx may allow remote attackers to obtain sensitive information. nginx 2015-02-07 2015-02-07 522994 remote 1.7.6 1.7.6

nginx is a robust, small, and high performance HTTP and reverse proxy server.

An SSL session fixation vulnerability has been found in nginx when multiple servers use the same shared ssl_session_cache or ssl_session_ticket_key.

A remote attacker may be able to obtain sensitive information.

There is no known workaround at this time.

All nginx users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/nginx-1.7.6"
CVE-2014-3616 Zlogene ackle