Commit 72b2c8de authored by William A. Rowe Jr's avatar William A. Rowe Jr
Browse files

Non-releases don't have user-visible regressions; now a contributor to the fix

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1167151 13f79535-47bb-0310-9956-ffa450edef68
parent 914bd537
Loading
Loading
Loading
Loading
+3 −5
Changes for CHANGES: 3 added lines, 5 removed lines.
Original line number Diff line number Diff line
                                                         -*- coding: utf-8 -*-
                                                         -*- coding: utf-8 -*-
Changes with Apache 2.3.15

  *) SECURITY: CVE-2011-3192 (cve.mitre.org)
     core: Fix handling of byte-range requests to use less memory, to avoid
     denial of service. If the sum of all ranges in a request is larger than
     the original file, ignore the ranges and send the complete file.
     PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener]
     PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener,
     <lowprio20 gmail.com>]

  *) mod_ldap: Optional function uldap_ssl_supported(r) always returned false
     if called from a virtual host with mod_ldap directives in it.  Did not
@@ -24,9 +25,6 @@ Changes with Apache 2.3.15
     CRL processing to OpenSSL, and add a new [Proxy]CARevocationCheck
     directive for controlling the revocation checking mode. [Kaspar Brand]

  *) Fix a regression in the CVE-2011-3192 byterange fix.
     PR 51748. [low_priority <lowprio20 gmail.com>]

  *) core: Add MaxRanges directive to control the number of ranges permitted
     before returning the entire resource, with a default limit of 200. 
     [Eric Covener]