httpd-cvs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From j..@apache.org
Subject svn commit: r4620 - in /dev/httpd: Announcement2.4.html Announcement2.4.txt
Date Tue, 11 Mar 2014 16:32:17 GMT
Author: jim
Date: Tue Mar 11 16:32:17 2014
New Revision: 4620

Log:
And prep the draft announcements

Modified:
    dev/httpd/Announcement2.4.html
    dev/httpd/Announcement2.4.txt

Modified: dev/httpd/Announcement2.4.html
==============================================================================
--- dev/httpd/Announcement2.4.html (original)
+++ dev/httpd/Announcement2.4.html Tue Mar 11 16:32:17 2014
@@ -15,33 +15,42 @@
 <img src="../../images/apache_sub.gif" alt="" />
 
 <h1>
-                       Apache HTTP Server 2.4.7 Released
+                       Apache HTTP Server 2.4.8 Released
 </h1>
 <p>
    The Apache Software Foundation and the Apache HTTP Server Project are
    pleased to <a href="http://www.apache.org/dist/httpd/Announcement2.4.html">announce</a>
-   the release of version 2.4.7 of the Apache
+   the release of version 2.4.8 of the Apache
    HTTP Server ("Apache").  This version of Apache is our latest GA
    release of the new generation 2.4.x branch of Apache HTTPD and
    represents fifteen years of
    innovation by the project, and is recommended over all previous releases. This
-   release of Apache is principally a feature
+   release of Apache is principally a security, feature
    and bug fix release.
 </p>
+<ul>
+<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0098">CVE-2014-0098</a>
+     Segfaults with truncated cookie logging.
+     mod_log_config: Prevent segfaults when logging truncated
+     cookies. Clean up the cookie logging parser to recognize
+     only the cookie=value pairs, not valueless cookies.
+</li>
+</ul>
 <p>
    Also in this release are some exciting new features including:
 </p>
 <ul>
-    <li>Major updates to mod_proxy_fcgi</li>
-    <li>Higher performant event MPM</li>
-    <li>Enhancements to the WinNT MPM</li>
+    <li>Finer control over scoping of RewriteRules</li>
+    <li>Unix Domain Socket (UDS) support for mod_proxy backends.</li>
+    <li>Support for larger shared memory sizes for mod_socache_shmcb</li>
+    <li>mod_lua and mod_ssl enhancements</li>
 </ul>
 <p>
    We consider this release to be the best version of Apache available, and
    encourage users of all prior versions to upgrade.
 </p>
 <p>
-   Apache HTTP Server 2.4.7 is available for download from:
+   Apache HTTP Server 2.4.8 is available for download from:
 </p>
 <dl>
   <dd><a href="http://httpd.apache.org/download.cgi"
@@ -49,7 +58,7 @@
 </dl>
 <p>
    Please see the CHANGES_2.4 file, linked from the download page, for a
-   full list of changes.  A condensed list, CHANGES_2.4.7 includes only
+   full list of changes.  A condensed list, CHANGES_2.4.8 includes only
    those changes introduced since the prior 2.4 release.  A summary of all 
    of the security vulnerabilities addressed in this and earlier releases 
    is available:

Modified: dev/httpd/Announcement2.4.txt
==============================================================================
--- dev/httpd/Announcement2.4.txt (original)
+++ dev/httpd/Announcement2.4.txt Tue Mar 11 16:32:17 2014
@@ -1,24 +1,30 @@
-                Apache HTTP Server 2.4.7 Released
+                Apache HTTP Server 2.4.8 Released
 
    The Apache Software Foundation and the Apache HTTP Server Project
-   are pleased to announce the release of version 2.4.7 of the Apache
+   are pleased to announce the release of version 2.4.8 of the Apache
    HTTP Server ("Apache").  This version of Apache is our latest GA
    release of the new generation 2.4.x branch of Apache HTTPD and
    represents fifteen years of innovation by the project, and is
    recommended over all previous releases. This release of Apache is
-   principally a feature and bug fix release.
+   principally a security, feature and bug fix release.
 
+   CVE-2014-0098 (cve.mitre.org)
+     Segfaults with truncated cookie logging.
+     mod_log_config: Prevent segfaults when logging truncated
+     cookies. Clean up the cookie logging parser to recognize
+     only the cookie=value pairs, not valueless cookies.
 
    Also in this release are some exciting new features including:
 
-    *) Major updates to mod_proxy_fcgi
-    *) Higher performant event MPM
-    *) Enhancements to the WinNT MPM
+    *) Finer control over scoping of RewriteRules
+    *) Unix Domain Socket (UDS) support for mod_proxy backends.
+    *) Support for larger shared memory sizes for mod_socache_shmcb
+    *) mod_lua and mod_ssl enhancements
 
    We consider this release to be the best version of Apache available, and
    encourage users of all prior versions to upgrade.
 
-   Apache HTTP Server 2.4.7 is available for download from:
+   Apache HTTP Server 2.4.8 is available for download from:
 
      http://httpd.apache.org/download.cgi
 
@@ -29,7 +35,7 @@
      http://httpd.apache.org/docs/trunk/new_features_2_4.html
 
    Please see the CHANGES_2.4 file, linked from the download page, for a
-   full list of changes. A condensed list, CHANGES_2.4.7 includes only
+   full list of changes. A condensed list, CHANGES_2.4.8 includes only
    those changes introduced since the prior 2.4 release.  A summary of all 
    of the security vulnerabilities addressed in this and earlier releases 
    is available:



Mime
View raw message