diff options
author | Stefan Fritsch <sf@sfritsch.de> | 2013-05-30 15:13:45 +0200 |
---|---|---|
committer | Stefan Fritsch <sf@sfritsch.de> | 2013-05-30 15:13:45 +0200 |
commit | c7f1a230b9560109b16b910665fd4d3860cb6602 (patch) | |
tree | 3347b174bda9150e22794fa651d45ab4494d1cc6 | |
parent | ef1ca7c3f2a232ccc8da4091d2d93668bdb33ad9 (diff) | |
download | apache2-c7f1a230b9560109b16b910665fd4d3860cb6602.tar.gz |
Add note to README.Debian about CVE-2013-0966
-rw-r--r-- | debian/apache2.README.Debian | 11 | ||||
-rw-r--r-- | debian/changelog | 2 |
2 files changed, 13 insertions, 0 deletions
diff --git a/debian/apache2.README.Debian b/debian/apache2.README.Debian index e4e7f3bc..825c5e38 100644 --- a/debian/apache2.README.Debian +++ b/debian/apache2.README.Debian @@ -282,6 +282,17 @@ time and the default suexec mechanism can be picked by using the update-alternatives(8) system. +Unicode File Name Normalization +=============================== + +Using Apache with the document root on a file system that does unicode +normalization on the filenames can cause security issues. In Debian, +this affects ZFS with the non-default option to enable filename normalization, +and HFS+. It is strongly recommended not to use Apache with such file systems. +More information about this issue can be found by searching the web for +CVE-2013-0966. + + Documentation ============= diff --git a/debian/changelog b/debian/changelog index 6fa2588c..4e9949ae 100644 --- a/debian/changelog +++ b/debian/changelog @@ -6,6 +6,8 @@ apache2 (2.4.4-4) UNRELEASED; urgency=low - fix pod error - add overrides for hardening-no-fortify-functions - don't use /lib/init/vars.sh in init script + * Add note to README.Debian about CVE-2013-0966 if the document root is + on HFS+ or on ZFS with filename normalization. [ Arno Töll ] * Correct maintainer scripts by removing forgotten left-overs of our Squeeze |