diff options
| author | Stefan Fritsch <sf@sfritsch.de> | 2011-12-27 19:43:20 +0100 |
|---|---|---|
| committer | Stefan Fritsch <sf@sfritsch.de> | 2011-12-27 19:43:20 +0100 |
| commit | 0890390c00801651d08d3794e13b31a5dabbf5ef (patch) | |
| tree | 02483bc55903044385bb168f7b91e06296f7da25 /CHANGES | |
| parent | 14a509fc3b1f16381b86dc746807a063d8562149 (diff) | |
| download | apache2-0890390c00801651d08d3794e13b31a5dabbf5ef.tar.gz | |
Upstream tarball 2.2.21upstream/2.2.21
Diffstat (limited to 'CHANGES')
| -rw-r--r-- | CHANGES | 36 |
1 files changed, 35 insertions, 1 deletions
@@ -1,4 +1,38 @@ - -*- coding: utf-8 -*- + -*- coding: utf-8 -*- +Changes with Apache 2.2.21 + + *) SECURITY: CVE-2011-3348 (cve.mitre.org) + mod_proxy_ajp: Respond with HTTP_NOT_IMPLEMENTED when the method is not + recognized. [Jean-Frederic Clere] + + *) Fix a regression introduced by the CVE-2011-3192 byterange fix in 2.2.20. + PR 51748. [<lowprio20 gmail.com>] + + *) mod_filter: Instead of dropping the Accept-Ranges header when a filter + registered with AP_FILTER_PROTO_NO_BYTERANGE is present, + set the header value to "none". [Eric Covener, Ruediger Pluem] + + *) mod_proxy_ajp: Ignore flushing if headers have not been sent. + PR 51608 [Ruediger Pluem] + + *) mod_dav_fs: Fix segfault if apr DBM driver cannot be loaded. PR 51751. + [Stefan Fritsch] + + *) mod_alias: Adjust log severity of "incomplete redirection target" + message. PR 44020. + + *) mod_rewrite: Check validity of each internal (int:) RewriteMap even if the + RewriteEngine is disabled in server context, avoiding a crash while + referencing the invalid int: map at runtime. PR 50994. + [Ben Noordhuis <info noordhuis nl>] + + *) core: Allow MaxRanges none|unlimited|default and set 'Accept-Ranges: none' + in the case Ranges are being ignored with MaxRanges none. + [Eric Covener] + + *) mod_proxy_ajp: Respect "reuse" flag in END_REPONSE packets. + [Rainer Jung] + Changes with Apache 2.2.20 *) SECURITY: CVE-2011-3192 (cve.mitre.org) |
