~ubuntu-branches/ubuntu/hardy/apache2/hardy-security

« back to all changes in this revision

Viewing changes to debian/changelog

  • Committer: Bazaar Package Importer
  • Author(s): Marc Deslauriers
  • Date: 2009-07-09 14:53:32 UTC
  • mfrom: (27.1.2 hardy-proposed)
  • Revision ID: james.westby@ubuntu.com-20090709145332-2enq0fimjpt91qpk
Tags: 2.2.8-1ubuntu0.10
* SECURITY UPDATE: remote denial of service in the mod_proxy module via
  amount of streamed data that exceeds the Content-Length value
  - debian/patches/204_CVE-2009-1890.dpatch: make sure Content-Length is
    sane and check the length of the data in modules/proxy/mod_proxy_http.c
  - CVE-2009-1890
* SECURITY UPDATE: remote denial of service in mod_deflate module when
  the network connection was closed before compression completed
  - debian/patches/205_CVE-2009-1891.dpatch: fail if the connection has
    been aborted in server/core_filters.c
  - CVE-2009-1891

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
apache2 (2.2.8-1ubuntu0.10) hardy-security; urgency=low
 
2
 
 
3
  * SECURITY UPDATE: remote denial of service in the mod_proxy module via
 
4
    amount of streamed data that exceeds the Content-Length value
 
5
    - debian/patches/204_CVE-2009-1890.dpatch: make sure Content-Length is
 
6
      sane and check the length of the data in modules/proxy/mod_proxy_http.c
 
7
    - CVE-2009-1890
 
8
  * SECURITY UPDATE: remote denial of service in mod_deflate module when
 
9
    the network connection was closed before compression completed
 
10
    - debian/patches/205_CVE-2009-1891.dpatch: fail if the connection has
 
11
      been aborted in server/core_filters.c
 
12
    - CVE-2009-1891
 
13
 
 
14
 -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Thu, 09 Jul 2009 14:53:32 -0400
 
15
 
 
16
apache2 (2.2.8-1ubuntu0.9) hardy-proposed; urgency=low
 
17
 
 
18
  * debian/patches//101_fix-spinning-mod_proxy.dpatch: Fix mod_proxy
 
19
    with SSL using all the CPU. (LP: #306293)
 
20
 
 
21
 -- Chuck Short <zulcss@ubuntu.com>  Fri, 13 Feb 2009 15:43:29 +0000
 
22
 
1
23
apache2 (2.2.8-1ubuntu0.8) hardy-security; urgency=low
2
24
 
3
25
  * SECURITY UPDATE: Includes option could be overridden via .htaccess file