Security update for nginx
This update for nginx fixes the following issues: nginx was updated to 1.16.1 (jsc#ECO-1401) - Added TLS 1.3 support (jsc#SLE-9295, bsc#1150711) - Replaced obsolete GeoIP module with MaxMinDB-based GeoIP2 (jsc#SLE-11184, bsc#1156202) - Started nginx after network is online (bsc#1155690) - CVE-2019-20372: Fixed an HTTP request smuggling with certain error_page configurations which could have allowed unauthorized web page reads (bsc#1160682).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nginx fixes the following issues: nginx was updated to 1.16.1 (jsc#ECO-1401) - Added TLS 1.3 support (jsc#SLE-9295, bsc#1150711) - Replaced obsolete GeoIP module with MaxMinDB-based GeoIP2 (jsc#SLE-11184, bsc#1156202) - Started nginx after network is online (bsc#1155690) - CVE-2019-20372: Fixed an HTTP request smuggling with certain error_page configurations which could have allowed unauthorized web page reads (bsc#1160682).
05 / REFERENCES