Commit 2dbbd0eb authored by Paul Querna's avatar Paul Querna
Browse files

Fix the CHANGES to reflect when things were really fixed. Also remove the...

Fix the CHANGES to reflect when things were really fixed. Also remove the security tag from the proxy change, as suggested by Joe.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@209832 13f79535-47bb-0310-9956-ffa450edef68
parent c52a9933
Loading
Loading
Loading
Loading
+6 −7
Changes for CHANGES: 6 added lines, 7 removed lines.
Original line number Diff line number Diff line
@@ -20,11 +20,15 @@ Changes with Apache 2.1.7
Changes with Apache 2.1.6
  *) SECURITY: CAN-2005-2088
     core: If a request contains both Transfer-Encoding and a Content-Length,
     remove the Content-Length, stopping some HTTP Request smuggling attacks.
     [Paul Querna]
  *) Fix htdbm password validation for records which included comments.
     [Eric Covener <covener gmail.com>]
  *) SECURITY: CAN-2005-2088
     proxy HTTP: If a response contains both Transfer-Encoding and a 
  *) proxy HTTP: If a response contains both Transfer-Encoding and a 
     Content-Length, remove the Content-Length and don't reuse the
     connection, stopping some HTTP Request smuggling attacks.
     [Jeff Trawick]
@@ -34,11 +38,6 @@ Changes with Apache 2.1.6
Changes with Apache 2.1.5
  *) SECURITY: CAN-2005-2088
     core: If a request contains both Transfer-Encoding and a Content-Length,
     remove the Content-Length, stopping some HTTP Request smuggling attacks.
     [Paul Querna]
  *) mod_ssl: Setting the Protocol to 'https' can replace the use of the 
     'SSLEngine on' command. [Paul Querna]