Commit a05be709 authored by Jim Jagielski's avatar Jim Jagielski
Browse files

in 2.2.9


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@666291 13f79535-47bb-0310-9956-ffa450edef68
parent 4786bc4e
Loading
Loading
Loading
Loading
+0 −6
Changes for CHANGES: 0 added lines, 6 removed lines.
Original line number Diff line number Diff line
@@ -2,12 +2,6 @@
Changes with Apache 2.3.0
[ When backported to 2.2.x, remove entry from this file ]

  *) SECURITY: CVE-2008-2364 (cve.mitre.org)
     mod_proxy_http: Better handling of excessive interim responses
     from origin server to prevent potential denial of service and high
     memory usage. Reported by Ryujiro Shibuya. [Ruediger Pluem,
     Joe Orton, Jim Jagielski]

  *) mod_proxy_http: Do not forward requests with 'Expect: 100-continue' to
     known HTTP/1.0 servers. Return 'Expectation failed' (417) instead.
     [Ruediger Pluem]