Return-Path: Delivered-To: apmail-httpd-cvs-archive@www.apache.org Received: (qmail 97248 invoked from network); 15 Dec 2007 15:43:16 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 15 Dec 2007 15:43:16 -0000 Received: (qmail 20685 invoked by uid 500); 15 Dec 2007 15:43:05 -0000 Delivered-To: apmail-httpd-cvs-archive@httpd.apache.org Received: (qmail 20640 invoked by uid 500); 15 Dec 2007 15:43:05 -0000 Mailing-List: contact cvs-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: dev@httpd.apache.org list-help: list-unsubscribe: List-Post: List-Id: Delivered-To: mailing list cvs@httpd.apache.org Received: (qmail 20623 invoked by uid 99); 15 Dec 2007 15:43:05 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Sat, 15 Dec 2007 07:43:05 -0800 X-ASF-Spam-Status: No, hits=-100.0 required=10.0 tests=ALL_TRUSTED X-Spam-Check-By: apache.org Received: from [140.211.11.3] (HELO eris.apache.org) (140.211.11.3) by apache.org (qpsmtpd/0.29) with ESMTP; Sat, 15 Dec 2007 15:42:52 +0000 Received: by eris.apache.org (Postfix, from userid 65534) id 91E091A9851; Sat, 15 Dec 2007 07:42:43 -0800 (PST) Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: svn commit: r604441 - /httpd/httpd/branches/2.0.x/CHANGES Date: Sat, 15 Dec 2007 15:42:43 -0000 To: cvs@httpd.apache.org From: rpluem@apache.org X-Mailer: svnmailer-1.0.8 Message-Id: <20071215154243.91E091A9851@eris.apache.org> X-Virus-Checked: Checked by ClamAV on apache.org Author: rpluem Date: Sat Dec 15 07:42:42 2007 New Revision: 604441 URL: http://svn.apache.org/viewvc?rev=604441&view=rev Log: * Wrong order, Security changes first. Modified: httpd/httpd/branches/2.0.x/CHANGES Modified: httpd/httpd/branches/2.0.x/CHANGES URL: http://svn.apache.org/viewvc/httpd/httpd/branches/2.0.x/CHANGES?rev=604441&r1=604440&r2=604441&view=diff ============================================================================== --- httpd/httpd/branches/2.0.x/CHANGES [utf-8] (original) +++ httpd/httpd/branches/2.0.x/CHANGES [utf-8] Sat Dec 15 07:42:42 2007 @@ -1,6 +1,10 @@ -*- coding: utf-8 -*- Changes with Apache 2.0.62 + *) SECURITY: CVE-2007-5000 (cve.mitre.org) + mod_imagemap: Fix a cross-site scripting issue. Reported by JPCERT. + [Joe Orton] + *) http_protocol: Escape request method in 405 error reporting. This has no security impact since the browser cannot be tricked into sending arbitrary method strings. [Jeff Trawick] @@ -8,10 +12,6 @@ *) http_protocol: Escape request method in 413 error reporting. Determined to be not generally exploitable, but a flaw in any case. PR 44014 [Victor Stinner ] - - *) SECURITY: CVE-2007-5000 (cve.mitre.org) - mod_imagemap: Fix a cross-site scripting issue. Reported by JPCERT. - [Joe Orton] Changes with Apache 2.0.61