Commit 970eadfa authored by Stefan Fritsch's avatar Stefan Fritsch
Browse files

The vulnerable code was not in 2.2.16's mod_reqtimeout, therefore we

don't need to mention CVE-2010-1623 in the changelog.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1005957 13f79535-47bb-0310-9956-ffa450edef68
parent 15109e4e
Loading
Loading
Loading
Loading
+0 −4
Changes for CHANGES: 0 added lines, 4 removed lines.
Original line number Diff line number Diff line
                                                         -*- coding: utf-8 -*-
Changes with Apache 2.2.17

  *) SECURITY: CVE-2010-1623 (cve.mitre.org)
     Fix a denial of service attack against mod_reqtimeout.
     [Stefan Fritsch]

  *) mod_reqtimeout: Do not wrongly enforce timeouts for mod_proxy's backend
     connections and other protocol handlers (like mod_ftp). Enforce the
     timeout for AP_MODE_GETLINE. If there is a timeout, shorten the lingering