Nginx security update
seclists.org
seclists.org
Patched source was actually posted back on May 7th and 13th for people who compile their own builds.
2013-05-07 nginx-1.4.1 stable and nginx-1.5.0 development versions have been released,
with the fix for the stack-based buffer overflow security problem in nginx 1.3.9 - 1.4.0,
discovered by Greg MacManus, of iSIGHT Partners Labs (CVE-2013-2028).
2013-05-13 nginx-1.2.9 legacy version has been released, addressing the information
disclosure security problem in some previous nginx versions (CVE-2013-2070).This is almost 2 months old.
It would seem to me that this is a particularly rare use case of nginx?
I suppose shared web hosts and services like CloudFlare are the types of implementation that may be affected.
It's not that common, but I know at least an app using nginx in that way, and it was performing very well.