summaryrefslogtreecommitdiff
path: root/debian/changelog
diff options
context:
space:
mode:
authorStefan Fritsch <sf@sfritsch.de>2015-08-02 00:38:09 +0200
committerStefan Fritsch <sf@sfritsch.de>2015-08-02 00:38:51 +0200
commitd94235c7e636826467e6ac51829f7ab7ed0afa71 (patch)
treeb52644aafd60669c81cab4b75abb91f6ca194701 /debian/changelog
parentf61517b82ffe096daa5ff5421d89ccfe21e0a336 (diff)
downloadapache2-d94235c7e636826467e6ac51829f7ab7ed0afa71.tar.gz
Adjustments for 2.4.16
* remove obsolete patches * add changelog entry
Diffstat (limited to 'debian/changelog')
-rw-r--r--debian/changelog10
1 files changed, 9 insertions, 1 deletions
diff --git a/debian/changelog b/debian/changelog
index a273fcf2..021840fb 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,5 +1,13 @@
-apache2 (2.4.12-3) UNRELEASED; urgency=medium
+apache2 (2.4.16-1) UNRELEASED; urgency=medium
+ [ Stefan Fritsch ]
+ * New upstream version, fixing the following security issues:
+ + CVE-2015-3183: Fix chunk header parsing defect.
+ + CVE-2015-3185: ap_some_auth_required() broken in apache 2.4 in an
+ unfixable way. Add a new replacement API ap_some_authn_required()
+ and ap_force_authn hook.
+
+ [ Jean-Michel Vourgère ]
* Allow "triggers-awaited" and "triggers-pending" states in addition to
"installed" when determining whether to defer actions or process
deferred actions. Thanks Colin Watson. Closes: #787103