Just patch it.
Just patch it.
I'm not complaining. It doesn't happen to me that often. Way more often, it's someone complaining about some anonymous employer or service provider and 20 people writing comments about how it's irresponsible for them not to say who it was. But it's the same kind of annoying every time.
Maybe the term ought to be in German. German works great for concepts like this.
Why did I leave the comment? Because it's hard to patch server software and people will often wait on patches until maintenance windows (advise you not do that this time) or take some time to figure out if they're affected. Especially with Apache, where oftentimes you aren't affected because the bug is in some random module most people don't use.
Don't take this the wrong way, but I think it was the tone of the response.
I.e. "What are the implications of this?" "It's a bad bug, patch it ASAP" "....."
It's the kind of non-response one would expect from a management type to a low level engineer. Somewhat odious to the average hacker, in other words.
(I could be COMPLETELY off the mark here, and if so, please disregard this entire message)
As to the average hacker, yes we want to know everything, but there are valid reasons not to be told everything. In this case, the information given is useful and sufficient, and the implications of what he said and how he said it are very clear indeed.
As for how many people it practically affects, that could well hurt. Saying anything more than "Applications are broadly vulnerable to this problem." like he did elsewhere in this thread could very well point out specific, detectable vulnerable instances. That's a bad thing. Just wait and more info will be out, but heed his advice!
(I said, when his comment was light grey...)
Master tracking bug: https://bugzilla.redhat.com/show_bug.cgi?id=803856
EPEL: https://bugzilla.redhat.com/show_bug.cgi?id=803859
Fedora: https://bugzilla.redhat.com/show_bug.cgi?id=803858
RPMs for 1.0.14 are available in koji at those second two links, or you can grab it via "yum --enablerepo=updates-testing update nginx" once the mirrors all pick it up.