A vulnerability was found in nginx code responsible for saving client request body to a temporary file. A specially crafted request might result in worker process crash due to a NULL pointer dereference while writing client request body to a temporary file.
External references:
http://mailman.nginx.org/pipermail/nginx-announce/2016/000179.html
Upstream patches:
[nginx 1.9.13 - 1.11.0] http://nginx.org/download/patch.2016.write.txt
[nginx 1.3.9 - 1.9.12] http://nginx.org/download/patch.2016.write2.txt