You are viewing a plain text version of this content. The canonical link for it is here.
Posted to cvs@httpd.apache.org by wr...@apache.org on 2010/03/06 03:13:49 UTC

svn commit: r88 - in /dev/httpd: Announcement2.2.html Announcement2.2.txt

Author: wrowe
Date: Fri Mar  5 21:13:48 2010
New Revision: 88

Log:
A draft announcement for tomorrow morning as mirrors have caught up.

Comments?

Added:
    dev/httpd/Announcement2.2.html
      - copied, changed from r79, release/httpd/Announcement2.2.html
    dev/httpd/Announcement2.2.txt
      - copied, changed from r79, release/httpd/Announcement2.2.txt

Copied: dev/httpd/Announcement2.2.html (from r79, release/httpd/Announcement2.2.html)
==============================================================================
--- release/httpd/Announcement2.2.html (original)
+++ dev/httpd/Announcement2.2.html Fri Mar  5 21:13:48 2010
@@ -14,84 +14,86 @@
 >
 <img src="../../images/apache_sub.gif" alt="">
 
-<h1>Apache HTTP Server 2.2.14 Released</h1>
+<h1>
+                  Apache HTTP Server (httpd) 2.2.15 Released
+</h1>
 
 <p>
    The Apache Software Foundation and the Apache HTTP Server Project are
-   pleased to announce the release of version 2.2.14 of the Apache HTTP
-   Server ("Apache").  This version of Apache is principally a security
-   and bug fix release.  Notably, this version bundles the APR Library
-   version 1.3.9, which addresses a security concern with the Prefork
-   and Event MPMs on Solaris 10.
+   pleased to announce the release and immediate availability of version
+   2.2.15 of the Apache HTTP Server ("httpd").  This version of httpd is 
+   principally a security and bug fix release.
 </p>
 
 <p>
-We consider this release to be the best version of Apache available, and
-encourage users of all prior versions to upgrade.
+   Notably, this release was updated to reflect the OpenSSL Project's
+   release 0.9.8m of the openssl library, and addresses CVE-2009-3555 
+   (cve.mitre.org), the TLS renegotiation prefix injection attack.
+   This release further addresses the issues CVE-2010-0408, CVE-2010-0425
+   and CVE-2010-0434 within mod_proxy_ajp, mod_isapi and mod_headers
+   respectively.
 </p>
 
-<p>Apache HTTP Server 2.2.14 is available for download from:</p>
-<dl>
-  <dd><a href="http://httpd.apache.org/download.cgi"
-              >http://httpd.apache.org/download.cgi</a></dd>
-</dl>
+<p>
+   We consider this release to be the best version of httpd available, and
+   encourage users of all prior versions to upgrade.
+</p>
 
 <p>
-Apache 2.2 offers numerous enhancements, improvements, and performance
-boosts over the 2.0 codebase.  For an overview of new features introduced
-since 2.0 please see:
+   Apache HTTP Server 2.2.15 is available for download from:
 </p>
 
 <dl>
-     <dd><a href="http://httpd.apache.org/docs/2.2/new_features_2_2.html">
-         http://httpd.apache.org/docs/2.2/new_features_2_2.html</a></dd>
+  <dd><a href="http://httpd.apache.org/download.cgi"
+              >http://httpd.apache.org/download.cgi</a>
+  </dd>
 </dl>
 
 <p>
-Please see the CHANGES_2.2 file, linked from the download page, for a
-full list of changes.  A condensed list, CHANGES_2.2.14 provides the
-complete list of changes since 2.2.13.
-A summary of security vulnerabilities
-which were  addressed in the previous 2.2.13 and earlier releases is available:
-<dl>
-  <dd><a href="http://httpd.apache.org/security/vulnerabilities_22.html"
-              >http://httpd.apache.org/security/vulnerabilities_22.html</a>
-</dd></dl>
+   Please see the CHANGES_2.2 file, linked from the download page, for a
+   full list of changes.  A condensed list, CHANGES_2.2.15 provides the
+   complete list of changes since 2.2.14. A summary of security
+   vulnerabilities which were addressed in the previous 2.2.14 and earlier
+   releases is available:
 </p>
 
-<p>
-Apache HTTP Server 1.3.41 and 2.0.63 legacy releases are also currently
-available.  See the corresponding CHANGES files linked from the download page.
-The Apache HTTP Project developers strongly encourage all users to migrate 
-to  Apache 2.2, as only limited maintenance is performed for these legacy 
-releases.
-</p>
+<dl>
+  <dd><a href="http://httpd.apache.org/security/vulnerabilities_22.html">
+               http://httpd.apache.org/security/vulnerabilities_22.html</a>
+  </dd>
+</dl>
 
 <p>
-This release includes the <a href="http://apr.apache.org/"
->Apache Portable Runtime</a> (APR) version 1.3.9
-bundled with the tar and zip distributions.  The APR libraries libapr and
-libaprutil (and on Win32, libapriconv) must all be updated to ensure
-binary compatibility and address many known platform bugs.
+   This release includes the Apache Portable Runtime (APR) version 1.4.2 and
+   APR-util library version 1.3.9, bundled with the tar and zip distributions.
+   The APR libraries libapr and libaprutil (and on Win32, libapriconv) must 
+   all be updated to ensure binary compatibility and address many known
+   security and platform bugs.
 </p>
 
 <p>
-This release builds on and extends the Apache 2.0 API. Modules written for 
-Apache version 2.0 will need to be recompiled in order to run with Apache 2.2,
-and require minimal or no source code changes.
+   Apache HTTP Server 2.2 offers numerous enhancements, bug fixes, and
+   performance enhancements over the 2.0 codebase.  For an overview of
+   new features introduced since 2.0 please see:
 </p>
 
 <dl>
-  <dd><a 
-href="http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/VERSIONING"
-> http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/VERSIONING</a></dd>
+  <dd><a href="http://httpd.apache.org/docs/2.2/new_features_2_2.html"
+              >http://httpd.apache.org/docs/2.2/new_features_2_2.html</a>
+  </dd>
 </dl>
 
 <p>
-When upgrading or installing this version of Apache, please bear in mind
-that if you intend to use Apache with one of the threaded MPMs (other than
-the Prefork MPM), you must ensure that any modules you will be using (and 
-the libraries they depend on) are thread-safe.
+   This release builds upon and extends the httpd 2.0 API.  Modules written
+   for httpd 2.0 will need to be recompiled in order to run with httpd 2.2,
+   and may require minimal or no source code changes.
+</p>
+
+<p>
+   When upgrading or installing this version of httpd, please bear in mind
+   that if you intend to use httpd with one of the threaded MPMs (other
+   than the Prefork MPM), you must ensure that any modules you will be
+   using (and the libraries they depend on) are thread-safe.
 </p>
 
 </body>

Copied: dev/httpd/Announcement2.2.txt (from r79, release/httpd/Announcement2.2.txt)
==============================================================================
--- release/httpd/Announcement2.2.txt (original)
+++ dev/httpd/Announcement2.2.txt Fri Mar  5 21:13:48 2010
@@ -1,53 +1,49 @@
-                       Apache HTTP Server 2.2.14 Released
+                  Apache HTTP Server (httpd) 2.2.15 Released
 
    The Apache Software Foundation and the Apache HTTP Server Project are
-   pleased to announce the release of version 2.2.14 of the Apache HTTP
-   Server ("Apache").  This version of Apache is principally a security
-   and bug fix release.  Notably, this version bundles the APR Library
-   version 1.3.9, which addresses a security concern with the Prefork
-   and Event MPMs on Solaris 10.
+   pleased to announce the release and immediate availability of version
+   2.2.15 of the Apache HTTP Server ("httpd").  This version of httpd is 
+   principally a security and bug fix release.
+
+   Notably, this release was updated to reflect the OpenSSL Project's
+   release 0.9.8m of the openssl library, and addresses CVE-2009-3555 
+   (cve.mitre.org), the TLS renegotiation prefix injection attack.
+   This release further addresses the issues CVE-2010-0408, CVE-2010-0425
+   and CVE-2010-0434 within mod_proxy_ajp, mod_isapi and mod_headers
+   respectively.
 
-   We consider this release to be the best version of Apache available, and
+   We consider this release to be the best version of httpd available, and
    encourage users of all prior versions to upgrade.
 
-   Apache HTTP Server 2.2.14 is available for download from:
+   Apache HTTP Server 2.2.15 is available for download from:
 
      http://httpd.apache.org/download.cgi
 
-   Apache 2.2 offers numerous enhancements, improvements, and performance
-   boosts over the 2.0 codebase.  For an overview of new features
-   introduced since 2.0 please see:
-
-     http://httpd.apache.org/docs/2.2/new_features_2_2.html
-
    Please see the CHANGES_2.2 file, linked from the download page, for a
-   full list of changes.  A condensed list, CHANGES_2.2.14 provides the
+   full list of changes.  A condensed list, CHANGES_2.2.15 provides the
    complete list of changes since 2.2.14. A summary of security
-   vulnerabilities which were addressed in the previous 2.2.13 and earlier
+   vulnerabilities which were addressed in the previous 2.2.14 and earlier
    releases is available:
 
      http://httpd.apache.org/security/vulnerabilities_22.html
 
-   Apache HTTP Server 1.3.41 and 2.0.63 legacy releases are also currently
-   available.  See the appropriate CHANGES from the url above.  See the
-   corresponding CHANGES files linked from the download page.  The Apache
-   HTTP Project developers strongly encourage all users to migrate to
-   Apache 2.2, as only limited maintenance is performed on these legacy
-   versions.
-
-   This release includes the Apache Portable Runtime (APR) version 1.3.9
-   bundled with the tar and zip distributions.  The APR libraries libapr
-   and libaprutil (and on Win32, libapriconv) must all be updated to ensure
-   binary compatibility and address many known security and platform bugs.
-
-   This release builds on and extends the Apache 2.0 API.  Modules written
-   for Apache 2.0 will need to be recompiled in order to run with Apache
-   2.2, and require minimal or no source code changes.
+   This release includes the Apache Portable Runtime (APR) version 1.4.2 and
+   APR-util library version 1.3.9, bundled with the tar and zip distributions.
+   The APR libraries libapr and libaprutil (and on Win32, libapriconv) must 
+   all be updated to ensure binary compatibility and address many known
+   security and platform bugs.
+
+   Apache HTTP Server 2.2 offers numerous enhancements, bug fixes, and
+   performance enhancements over the 2.0 codebase.  For an overview of
+   new features introduced since 2.0 please see:
 
-     http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/VERSIONING
+     http://httpd.apache.org/docs/2.2/new_features_2_2.html
+
+   This release builds upon and extends the httpd 2.0 API.  Modules written
+   for httpd 2.0 will need to be recompiled in order to run with httpd 2.2,
+   and may require minimal or no source code changes.
 
-   When upgrading or installing this version of Apache, please bear in mind
-   that if you intend to use Apache with one of the threaded MPMs (other
+   When upgrading or installing this version of httpd, please bear in mind
+   that if you intend to use httpd with one of the threaded MPMs (other
    than the Prefork MPM), you must ensure that any modules you will be
    using (and the libraries they depend on) are thread-safe.
-