Commit 2dd09306 authored by Ruediger Pluem's avatar Ruediger Pluem
Browse files

* CVE-2006-3747 was the main reason to release 2.2.3. So place the changelog

  entry where it belongs.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@476628 13f79535-47bb-0310-9956-ffa450edef68
parent 66cb25a8
Loading
Loading
Loading
Loading
+6 −6
Changes for CHANGES: 6 added lines, 6 removed lines.
Original line number Diff line number Diff line
@@ -125,12 +125,6 @@ Changes with Apache 2.3.0
     his value is defined as 258, thus limiting the MaxThreads
     to that value. [Mladen Turk]
  *) SECURITY: CVE-2006-3747 (cve.mitre.org)
     mod_rewrite: Fix an off-by-one security problem in the ldap scheme
     handling.  For some RewriteRules this could lead to a pointer being
     written out of bounds.  Reported by Mark Dowd of McAfee.
     [Mark Cox]
  *) mod_cache: While serving a cached entity ensure that filters that have
     been applied to this cached entity before saving it to the cache are not
     applied again. PR 40090. [Ruediger Pluem]
@@ -345,6 +339,12 @@ Changes with Apache 2.2.4
Changes with Apache 2.2.3
  *) SECURITY: CVE-2006-3747 (cve.mitre.org)
     mod_rewrite: Fix an off-by-one security problem in the ldap scheme
     handling.  For some RewriteRules this could lead to a pointer being
     written out of bounds.  Reported by Mark Dowd of McAfee.
     [Mark Cox]
  *) mod_authn_alias: Add a check to make sure that the base provider and the
     alias names are different and also that the alias has not been registered
     before. PR 40051. [Brad Nicholes]