You are viewing a plain text version of this content. The canonical link for it is here.
Posted to cvs@httpd.apache.org by bu...@apache.org on 2012/09/26 13:39:49 UTC

svn commit: r833060 - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_22.html

Author: buildbot
Date: Wed Sep 26 11:39:49 2012
New Revision: 833060

Log:
Staging update by buildbot for httpd

Modified:
    websites/staging/httpd/trunk/content/   (props changed)
    websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml
    websites/staging/httpd/trunk/content/security/vulnerabilities_22.html

Propchange: websites/staging/httpd/trunk/content/
------------------------------------------------------------------------------
--- cms:source-revision (original)
+++ cms:source-revision Wed Sep 26 11:39:49 2012
@@ -1 +1 @@
-1389840
+1390413

Modified: websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml
==============================================================================
--- websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml (original)
+++ websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml Wed Sep 26 11:39:49 2012
@@ -1,6 +1,6 @@
-<security updated="20120920">
+<security updated="20120926">
 
-<issue fixed="2.2.23-dev" reported="20120531" public="20120613">
+<issue fixed="2.2.23" reported="20120531" public="20120613" released="20120913">
 <cve name="CVE-2012-2687"/>
 <severity level="4">low</severity>
 <title>XSS in mod_negotiation when untrusted uploads are supported</title>
@@ -62,7 +62,7 @@ between users.
 <affects prod="httpd" version="2.4.1"/>
 </issue>
 
-<issue fixed="2.2.23-dev" reported="20120214" public="20120302" released="20120417">
+<issue fixed="2.2.23" reported="20120214" public="20120302" released="20120913">
 <cve name="CVE-2012-0883"/>
 <severity level="4">low</severity>
 <title>insecure LD_LIBRARY_PATH handling</title>

Modified: websites/staging/httpd/trunk/content/security/vulnerabilities_22.html
==============================================================================
--- websites/staging/httpd/trunk/content/security/vulnerabilities_22.html (original)
+++ websites/staging/httpd/trunk/content/security/vulnerabilities_22.html Wed Sep 26 11:39:49 2012
@@ -83,8 +83,8 @@ in a "-dev" release then this means that
 the development source tree and will be part of an upcoming full release.</p><p> This page is created from a database of vulnerabilities originally
 populated by Apache Week.  Please send comments or corrections for
 these vulnerabilities to the <a href="/security_report.html">Security
-Team</a>.  </p><h1 id="2.2.23-dev">
-Fixed in Apache httpd 2.2.23-dev</h1><dl>
+Team</a>.  </p><h1 id="2.2.23">
+Fixed in Apache httpd 2.2.23</h1><dl>
   <dd>
     <b>low: </b>
     <b>
@@ -100,7 +100,8 @@ untrusted uploads to locations which hav
   <dd>
   Reported to security team: 31st May 2012<br/>
   Issue public: 13th June 2012<br/></dd>
-  <dd/>
+  <dd>
+  Update Released: 13th September 2012<br/></dd>
   <dd>
       Affects: 
     2.2.22, 2.2.21, 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0<p/></dd>
@@ -121,7 +122,7 @@ administrator runs apachectl from an unt
   Reported to security team: 14th February 2012<br/>
   Issue public: 2nd March 2012<br/></dd>
   <dd>
-  Update Released: 17th April 2012<br/></dd>
+  Update Released: 13th September 2012<br/></dd>
   <dd>
       Affects: 
     2.2.22, 2.2.21, 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0<p/></dd>