Path to this page:
Subject: CVS commit: pkgsrc/www/apache24
From: Ryo ONODERA
Date: 2013-07-30 14:51:29
Message id: 20130730125129.AA69496@cvs.netbsd.org
Log Message:
Update to 2.4.6
Changelog:
Security buxfixes.
SECURITY: CVE-2013-1896 (cve.mitre.org) Sending a MERGE request against a \
URI handled by mod_dav_svn with the source href (sent as part of the request \
body as XML) pointing to a URI that is not configured for DAV will trigger a \
segfault.
SECURITY: CVE-2013-2249 (cve.mitre.org) mod_session_dbd: Make sure that \
dirty flag is respected when saving sessions, and ensure the session ID is \
changed each time the session changes. This changes the format of the \
updatesession SQL statement. Existing configurations must be changed.
And feature enhancement and bugfixes.
Files: