~ubuntu-branches/ubuntu/jaunty/apache2/jaunty-security

« back to all changes in this revision

Viewing changes to debian/changelog

  • Committer: Bazaar Package Importer
  • Author(s): Jamie Strandboge
  • Date: 2009-06-10 17:15:00 UTC
  • Revision ID: james.westby@ubuntu.com-20090610171500-ll8ecx3dakxllzgn
Tags: 2.2.11-2ubuntu2.1
* SECURITY UPDATE: response data disclosure in mod_proxy_ajp when a client
  request with no request body was sent
  - debian/patches/900_CVE-2009-1191.dpatch: adjust
    modules/proxy/mod_proxy_ajp.c to not reuse a connection when the client
    closes a connection without sending a body
  - CVE-2009-1191
* SECURITY UPDATE: Includes option could be overridden via .htaccess file
  when AllowOverride restrictions do not permit it
  - debian/patches/900_CVE-2009-1195.dpatch: adjust server/config.c,
    server/core.c, modules/filters/mod_include.c, include/http_core.h to
    only enable .htaccess override when permitted.
  - CVE-2009-1195

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
apache2 (2.2.11-2ubuntu2.1) jaunty-security; urgency=low
 
2
 
 
3
  * SECURITY UPDATE: response data disclosure in mod_proxy_ajp when a client
 
4
    request with no request body was sent
 
5
    - debian/patches/900_CVE-2009-1191.dpatch: adjust
 
6
      modules/proxy/mod_proxy_ajp.c to not reuse a connection when the client
 
7
      closes a connection without sending a body
 
8
    - CVE-2009-1191
 
9
  * SECURITY UPDATE: Includes option could be overridden via .htaccess file
 
10
    when AllowOverride restrictions do not permit it
 
11
    - debian/patches/900_CVE-2009-1195.dpatch: adjust server/config.c,
 
12
      server/core.c, modules/filters/mod_include.c, include/http_core.h to
 
13
      only enable .htaccess override when permitted.
 
14
    - CVE-2009-1195
 
15
 
 
16
 -- Jamie Strandboge <jamie@ubuntu.com>  Wed, 10 Jun 2009 17:15:00 -0500
 
17
 
1
18
apache2 (2.2.11-2ubuntu2) jaunty; urgency=low
2
19
 
3
20
  * debian/patches/203_fix-ssi-timeftm-ignored.dpatch: