diff options
author | Eric Covener <covener@apache.org> | 2011-09-06 20:45:33 +0200 |
---|---|---|
committer | Eric Covener <covener@apache.org> | 2011-09-06 20:45:33 +0200 |
commit | 671fe792ccad54ccae2acd9854484a4df6af6041 (patch) | |
tree | 3526d234fd2192f04fcf4addcb7d8ae175bcdbbc /CHANGES | |
parent | * modules/http/byterange_filter.c (ap_byterange_filter): Don't reveal (diff) | |
download | apache2-671fe792ccad54ccae2acd9854484a4df6af6041.tar.xz apache2-671fe792ccad54ccae2acd9854484a4df6af6041.zip |
bump SECURITY issue to top of in-development 2.3.15 section.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1165779 13f79535-47bb-0310-9956-ffa450edef68
Diffstat (limited to 'CHANGES')
-rw-r--r-- | CHANGES | 12 |
1 files changed, 6 insertions, 6 deletions
@@ -1,6 +1,12 @@ -*- coding: utf-8 -*- Changes with Apache 2.3.15 + *) SECURITY: CVE-2011-3192 (cve.mitre.org) + core: Fix handling of byte-range requests to use less memory, to avoid + denial of service. If the sum of all ranges in a request is larger than + the original file, ignore the ranges and send the complete file. + PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener] + *) mod_ssl: revamp CRL-based revocation checking when validating certificates of clients or proxied servers. Completely delegate CRL processing to OpenSSL, and add a new [Proxy]CARevocationCheck @@ -9,12 +15,6 @@ Changes with Apache 2.3.15 *) Fix a regression in the CVE-2011-3192 byterange fix. PR 51748. [low_priority <lowprio20 gmail.com>] - *) SECURITY: CVE-2011-3192 (cve.mitre.org) - core: Fix handling of byte-range requests to use less memory, to avoid - denial of service. If the sum of all ranges in a request is larger than - the original file, ignore the ranges and send the complete file. - PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener] - *) core: Add MaxRanges directive to control the number of ranges permitted before returning the entire resource, with a default limit of 200. [Eric Covener] |