Browse Source

apache: Updated (2.2.20 -> 2.2.21) (SECURITY: CVE-2011-3348 CVE-2011-3192)

Note:

* SECURITY: CVE-2011-3348 (cve.mitre.org)

  mod_proxy_ajp when combined with mod_proxy_balancer: Prevents unrecognized
  HTTP methods from marking ajp: balancer members in an error state, avoiding
  denial of service.

* SECURITY: CVE-2011-3192 (cve.mitre.org)

  core: Further fixes to the handling of byte-range requests to use less
  memory, to avoid denial of service. This patch includes fixes to the patch
  introduced in release 2.2.20 for protocol compliance, as well as the
  MaxRanges directive.
user/amery/next/luajit
Christian Wiese 13 years ago
parent
commit
906ad1f9fc
  1. 4
      network/apache/apache.desc

4
network/apache/apache.desc

@ -37,7 +37,7 @@
[L] APL
[S] Stable
[V] 2.2.20
[V] 2.2.21
[P] X -----5---9 150.000
[D] 3578056022 httpd-2.2.20.tar.gz http://archive.apache.org/dist/httpd/
[D] 991599705 httpd-2.2.21.tar.gz http://archive.apache.org/dist/httpd/

Loading…
Cancel
Save