httpd-cvs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From traw...@apache.org
Subject svn commit: r1235894 - /httpd/httpd/branches/2.4.x/CHANGES
Date Wed, 25 Jan 2012 20:06:07 GMT
Author: trawick
Date: Wed Jan 25 20:06:07 2012
New Revision: 1235894

URL: http://svn.apache.org/viewvc?rev=1235894&view=rev
Log:
Add reference to CVE-2012-0021, quoting the 2.3.x version in which
the problem was introduced.

(following r1235875 which DidTRT for 2.2.x/CHANGES)

Modified:
    httpd/httpd/branches/2.4.x/CHANGES

Modified: httpd/httpd/branches/2.4.x/CHANGES
URL: http://svn.apache.org/viewvc/httpd/httpd/branches/2.4.x/CHANGES?rev=1235894&r1=1235893&r2=1235894&view=diff
==============================================================================
--- httpd/httpd/branches/2.4.x/CHANGES [utf-8] (original)
+++ httpd/httpd/branches/2.4.x/CHANGES [utf-8] Wed Jan 25 20:06:07 2012
@@ -24,8 +24,11 @@ Changes with Apache 2.4.0
 
   *) mod_ssl: Fix compilation with xlc on AIX. PR 52394. [Stefan Fritsch]
 
-  *) mod_log_config: Fix segfault when trying to log a nameless, valueless
-     cookie. PR 52256. [Rainer Canavan <rainer-apache 7val com>]
+  *) SECURITY: CVE-2012-0021 (cve.mitre.org)
+     mod_log_config: Fix segfault (crash) when the '%{cookiename}C' log format
+     string is in use and a client sends a nameless, valueless cookie, causing
+     a denial of service. The issue existed since version 2.2.17 and 2.3.3.
+     PR 52256.  [Stefan Fritsch]
 
   *) mod_ssl: when compiled against OpenSSL 1.0.1 or later, allow explicit
      control of TLSv1.1 and TLSv1.2 through the SSLProtocol directive.



Mime
View raw message