You are viewing a plain text version of this content. The canonical link for it is here.
Posted to cvs@httpd.apache.org by bu...@apache.org on 2012/09/26 13:39:49 UTC
svn commit: r833060 - in /websites/staging/httpd/trunk/content: ./
security/vulnerabilities-httpd.xml security/vulnerabilities_22.html
Author: buildbot
Date: Wed Sep 26 11:39:49 2012
New Revision: 833060
Log:
Staging update by buildbot for httpd
Modified:
websites/staging/httpd/trunk/content/ (props changed)
websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml
websites/staging/httpd/trunk/content/security/vulnerabilities_22.html
Propchange: websites/staging/httpd/trunk/content/
------------------------------------------------------------------------------
--- cms:source-revision (original)
+++ cms:source-revision Wed Sep 26 11:39:49 2012
@@ -1 +1 @@
-1389840
+1390413
Modified: websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml
==============================================================================
--- websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml (original)
+++ websites/staging/httpd/trunk/content/security/vulnerabilities-httpd.xml Wed Sep 26 11:39:49 2012
@@ -1,6 +1,6 @@
-<security updated="20120920">
+<security updated="20120926">
-<issue fixed="2.2.23-dev" reported="20120531" public="20120613">
+<issue fixed="2.2.23" reported="20120531" public="20120613" released="20120913">
<cve name="CVE-2012-2687"/>
<severity level="4">low</severity>
<title>XSS in mod_negotiation when untrusted uploads are supported</title>
@@ -62,7 +62,7 @@ between users.
<affects prod="httpd" version="2.4.1"/>
</issue>
-<issue fixed="2.2.23-dev" reported="20120214" public="20120302" released="20120417">
+<issue fixed="2.2.23" reported="20120214" public="20120302" released="20120913">
<cve name="CVE-2012-0883"/>
<severity level="4">low</severity>
<title>insecure LD_LIBRARY_PATH handling</title>
Modified: websites/staging/httpd/trunk/content/security/vulnerabilities_22.html
==============================================================================
--- websites/staging/httpd/trunk/content/security/vulnerabilities_22.html (original)
+++ websites/staging/httpd/trunk/content/security/vulnerabilities_22.html Wed Sep 26 11:39:49 2012
@@ -83,8 +83,8 @@ in a "-dev" release then this means that
the development source tree and will be part of an upcoming full release.</p><p> This page is created from a database of vulnerabilities originally
populated by Apache Week. Please send comments or corrections for
these vulnerabilities to the <a href="/security_report.html">Security
-Team</a>. </p><h1 id="2.2.23-dev">
-Fixed in Apache httpd 2.2.23-dev</h1><dl>
+Team</a>. </p><h1 id="2.2.23">
+Fixed in Apache httpd 2.2.23</h1><dl>
<dd>
<b>low: </b>
<b>
@@ -100,7 +100,8 @@ untrusted uploads to locations which hav
<dd>
Reported to security team: 31st May 2012<br/>
Issue public: 13th June 2012<br/></dd>
- <dd/>
+ <dd>
+ Update Released: 13th September 2012<br/></dd>
<dd>
Affects:
2.2.22, 2.2.21, 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0<p/></dd>
@@ -121,7 +122,7 @@ administrator runs apachectl from an unt
Reported to security team: 14th February 2012<br/>
Issue public: 2nd March 2012<br/></dd>
<dd>
- Update Released: 17th April 2012<br/></dd>
+ Update Released: 13th September 2012<br/></dd>
<dd>
Affects:
2.2.22, 2.2.21, 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0<p/></dd>