Candidate: CVE-2011-4968 PublicDate: 2019-11-19 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4968 http://mailman.nginx.org/pipermail/nginx-devel/2015-February/006484.html Description: nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) Ubuntu-Description: Notes: seth-arnold> Backporting this fix is non-trivial and may break deployed applications. Someone who really wanted this could use stunnel as a work-around until 16.04 LTS is released. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697940 https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1098654 http://trac.nginx.org/nginx/ticket/13 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N [4.8 MEDIUM] Patches_nginx: upstream: http://trac.nginx.org/nginx/changeset/060c2e692b96a150b584b8e30d596be1f2defa9c/nginx upstream_nginx: released (1.7.0) hardy_nginx: ignored (reached end-of-life) lucid_nginx: ignored (reached end-of-life) oneiric_nginx: ignored (reached end-of-life) precise_nginx: ignored (see notes) quantal_nginx: ignored (reached end-of-life) raring_nginx: ignored (reached end-of-life) saucy_nginx: ignored (reached end-of-life) trusty_nginx: ignored (see notes) trusty/esm_nginx: ignored (see notes) utopic_nginx: ignored (reached end-of-life) vivid_nginx: ignored (see notes) devel_nginx: not-affected (1.9.3-1ubuntu1)