You are viewing a plain text version of this content. The canonical link for it is here.
Posted to cvs@httpd.apache.org by ji...@apache.org on 2011/08/30 02:16:15 UTC

svn commit: r385 [3/3] - /dev/httpd/

Added: dev/httpd/CHANGES_2.2.20
==============================================================================
--- dev/httpd/CHANGES_2.2.20 (added)
+++ dev/httpd/CHANGES_2.2.20 Tue Aug 30 00:16:12 2011
@@ -0,0 +1,29 @@
+                                                         -*- coding: utf-8 -*-
+Changes with Apache 2.2.20
+
+  *) SECURITY: CVE-2011-3192 (cve.mitre.org)
+     core: Fix handling of byte-range requests to use less memory, to avoid
+     denial of service. If the sum of all ranges in a request is larger than
+     the original file, ignore the ranges and send the complete file.
+     PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener]
+
+  *) mod_authnz_ldap: If the LDAP server returns constraint violation,
+     don't treat this as an error but as "auth denied". [Stefan Fritsch]
+
+  *) mod_filter: Fix FilterProvider conditions of type "resp=" (response
+     headers) for CGI. [Joe Orton, Rainer Jung]
+
+  *) mod_reqtimeout: Fix a timed out connection going into the keep-alive
+     state after a timeout when discarding a request body. PR 51103.
+     [Stefan Fritsch]
+
+  *) core: Do the hook sorting earlier so that the hooks are properly sorted
+     for the pre_config hook and during parsing the config. [Stefan Fritsch]
+
+  [Apache 2.1.0-dev includes those bug fixes and changes with the
+   Apache 2.0.xx tree as documented, and except as noted, below.]
+
+Changes with Apache 2.0.x and later:
+
+  *) http://svn.apache.org/viewvc/httpd/httpd/branches/2.0.x/CHANGES?view=markup
+

Added: dev/httpd/httpd-2.2.20.tar.bz2
==============================================================================
Binary file - no diff available.

Propchange: dev/httpd/httpd-2.2.20.tar.bz2
------------------------------------------------------------------------------
    svn:mime-type = application/octet-stream

Added: dev/httpd/httpd-2.2.20.tar.bz2.asc
==============================================================================
--- dev/httpd/httpd-2.2.20.tar.bz2.asc (added)
+++ dev/httpd/httpd-2.2.20.tar.bz2.asc Tue Aug 30 00:16:12 2011
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v2.0.17 (Darwin)
+
+iQIVAwUATlwrRjTqduZ5FIWoAQogfA//cXvUzKuzgIvOm5lE2M8cs56+8Ik+cUGp
+G0aSyyxaQgTz54hDvL+er38DfE5dRHX32U8bYPSKolNbsoYXX5XvhK51VL5xLSwq
+R7tq9O0Z6mV+gBpfWy07yKoUDsGUIV6NKSYislW6v+Yi9as7BdXtKVQb8dJJU+g8
+hG0iGxTEWNQHGhY8lGVcevtCIzpK6CZ3oMm7lopgfAQbitG0kTmFLiOwDQDbUJIP
+5mruft+zDdxYQm1fcp3z/PmGWW+X0Z8kyIBZX45WGxhT67x6Q3P7KL5QE/kLf4im
+RjC0LlxdWjCm0xaGlPl8fAvNpk5t+M8V3s4ua+y+M94VQEGbRSo54zbWHnhSqugs
+iyQounuUqw9RqunQzC+aOYm5/MMSGmtg+tCWaGA1m5rJiDVo+ok8SRjNHUfkA2gd
+IoK433pdJOJTy7AVQi2IkCHJf7czoMBie+B5SXp3YdQRD+yGcqddQId5RcCnHjpb
+a8jZdEeoInqMpix6jbcOfKrbLZGE1NBPdPxD4QXejwtLT807q/F8QUwkNCmDpZDy
+n+a/t+3o51nUCdYvQBQJRkSgWkkVac2BArPZFUPd4ZVMQeXajoXHoYFthaemC7Ob
+b+FUPAfMGxlXeuEL2I2Y/VV78ZA6syApE97BFgvXgQJsBF3kKRrHApQqcwzFk+Ph
+S80gD/hU6oY=
+=CHZA
+-----END PGP SIGNATURE-----

Added: dev/httpd/httpd-2.2.20.tar.bz2.md5
==============================================================================
--- dev/httpd/httpd-2.2.20.tar.bz2.md5 (added)
+++ dev/httpd/httpd-2.2.20.tar.bz2.md5 Tue Aug 30 00:16:12 2011
@@ -0,0 +1 @@
+1ac251431c8c4285f6b085c1d156bb56 *httpd-2.2.20.tar.bz2

Added: dev/httpd/httpd-2.2.20.tar.bz2.sha1
==============================================================================
--- dev/httpd/httpd-2.2.20.tar.bz2.sha1 (added)
+++ dev/httpd/httpd-2.2.20.tar.bz2.sha1 Tue Aug 30 00:16:12 2011
@@ -0,0 +1 @@
+c8f00a505af6ed3f89f45b640217c388f5cd32b0 *httpd-2.2.20.tar.bz2

Added: dev/httpd/httpd-2.2.20.tar.gz
==============================================================================
Binary file - no diff available.

Propchange: dev/httpd/httpd-2.2.20.tar.gz
------------------------------------------------------------------------------
    svn:mime-type = application/octet-stream

Added: dev/httpd/httpd-2.2.20.tar.gz.asc
==============================================================================
--- dev/httpd/httpd-2.2.20.tar.gz.asc (added)
+++ dev/httpd/httpd-2.2.20.tar.gz.asc Tue Aug 30 00:16:12 2011
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v2.0.17 (Darwin)
+
+iQIVAwUATlwrRTTqduZ5FIWoAQri0w/+IJyNpZJ4hs4fMn7YW4o7Tf5217idz02A
+Fb1RjgKZ106GdkQxQARXHts4gJWqcd/yaSwu2ZAPbwGPFAn5ivoDRyMWL98P62zE
+saQ4DSb2K/KCJn2Xp3TkIheEJYg7Fihki0v4h+Yt4JgWhR5Bn7y3FkUwWeL8I1P/
+D/9X7Nll5xrZTK3hC0D0DeNjEveloe8Bfz35Am9WsoeJt8RBLQhdj3p94HXHV0qq
+rvebuhJTxJMpJBUJ+XQAWWGpzon6suJP9C1/bxmkPV8B3yLsf4PQVURwB2aRNhhu
+i2onGEYpW1QiWu2NaXXmGl2wPnSuSG+U6dNfULNhEwL5mBSI2ueb3y/80BtxlXoB
+0qOxDg68cm3vEAIKjUsFq0qoDpFLQ7LUlkORTatIPwt+MTEulWIZr6kdEGjMKX0Q
+m7QF3n4tA3GQ0TLDBSW/xN7uWlvRitR7To6NDbPmM5lrTJEN1eeGpzmcVzCaWE0S
+sLeJfyOCcuSAnkqO6lELI4owlF0Q0OyfCScYFeBD1sZQbXqaN/Ftj6qL520rUhJz
+sMGEEtqP3gPI3WTnL18MbChY5CnqDyXc9icQQ/O8kJnyKgkNnIfOAeKmNPJEslHj
+Wr17qv5WmPOa4dxWCX8QqpLHWYUY0E1AoTDyEGZwfKTzxQ6lFL1iv/vyGk/pHGTK
+w6m2SmPXtFU=
+=46Um
+-----END PGP SIGNATURE-----

Added: dev/httpd/httpd-2.2.20.tar.gz.md5
==============================================================================
--- dev/httpd/httpd-2.2.20.tar.gz.md5 (added)
+++ dev/httpd/httpd-2.2.20.tar.gz.md5 Tue Aug 30 00:16:12 2011
@@ -0,0 +1 @@
+4504934464c5ee51018dbafa6d99810d *httpd-2.2.20.tar.gz

Added: dev/httpd/httpd-2.2.20.tar.gz.sha1
==============================================================================
--- dev/httpd/httpd-2.2.20.tar.gz.sha1 (added)
+++ dev/httpd/httpd-2.2.20.tar.gz.sha1 Tue Aug 30 00:16:12 2011
@@ -0,0 +1 @@
+5e670636e17286b7ae5ade5b7f5e21e686559e5a *httpd-2.2.20.tar.gz