Commit f8b5b3fc authored by Paul Querna's avatar Paul Querna
Browse files

The request smuggling issue did get assigned CAN-2005-2088.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@209723 13f79535-47bb-0310-9956-ffa450edef68
parent b904c4e2
Loading
Loading
Loading
Loading
+2 −2
Changes for CHANGES: 2 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -19,7 +19,7 @@ Changes with Apache 2.1.6
  *) Fix htdbm password validation for records which included comments.
     [Eric Covener <covener gmail.com>]
  *) SECURITY: 
  *) SECURITY: CAN-2005-2088
     proxy HTTP: If a response contains both Transfer-Encoding and a 
     Content-Length, remove the Content-Length and don't reuse the
     connection, stopping some HTTP Request smuggling attacks.
@@ -30,7 +30,7 @@ Changes with Apache 2.1.6
Changes with Apache 2.1.5
  *) SECURITY: 
  *) SECURITY: CAN-2005-2088
     core: If a request contains both Transfer-Encoding and a Content-Length,
     remove the Content-Length, stopping some HTTP Request smuggling attacks.
     [Paul Querna]