4e04b29e6b
Changes with Apache 2.4.33 *) core: Fix request timeout logging and possible crash for error_log hooks. *) mod_slomem_shm: Fix failure to create balancers's slotmems in Windows MPM, where children processes need to attach them instead since they are owned by the parent process already. *) ab: try all destination socket addresses returned by apr_sockaddr_info_get instead of failing on first one when not available. Needed for instance if localhost resolves to both ::1 and 127.0.0.1 e.g. if both are in /etc/hosts. *) ab: Use only one connection to determine working destination socket address. *) ab: LibreSSL doesn't have or require Windows applink.c. *) htpasswd/htdigest: Disable support for bcrypt on EBCDIC platforms. apr-util's bcrypt implementation doesn't tolerate EBCDIC. *) htpasswd/htdbm: report the right limit when get_password() overflows. *) htpasswd: Don't fail in -v mode if password file is unwritable. *) htpasswd: don't point to (unused) stack memory on output to make static analysers happy. Changes with Apache 2.4.32 *) mod_access_compat: Fail if a comment is found in an Allow or Deny directive. *) mod_authz_host: Ignore comments after "Require host", logging a warning, or logging an error if the line is otherwise empty. *) rotatelogs: Fix expansion of %Z in localtime (-l) mode, and fix Y2K38 bug. *) mod_ssl: Support SSL DN raw variable extraction without conversion to UTF-8, using _RAW suffix on variable names. *) ab: Fix https:// connection failures (regression in 2.4.30); fix crash generating CSV output for large -n. Changes with Apache 2.4.31 *) mod_proxy_fcgi: Add the support for mod_proxy's flushpackets and flushwait parameters. *) mod_ldap: Avoid possible crashes, hangs, and busy loops due to improper merging of the cache lock in vhost config. *) mpm_event: Do lingering close in worker(s). *) mpm_queue: Put fdqueue code in common for MPMs event and worker. Changes with Apache 2.4.30 *) SECURITY: CVE-2017-15710 (cve.mitre.org) Out of bound write in mod_authnz_ldap with AuthLDAPCharsetConfig enabled *) CVE-2018-1283 (cve.mitre.org) mod_session: CGI-like applications that intend to read from mod_session's 'SessionEnv ON' could be fooled into reading user-supplied data instead. *) SECURITY: CVE-2018-1303 (cve.mitre.org) mod_cache_socache: Fix request headers parsing to avoid a possible crash with specially crafted input data. *) CVE-2018-1301 (cve.mitre.org) core: Possible crash with excessively long HTTP request headers. Impractical to exploit with a production build and production LogLevel. *) mod_authnz_ldap: Fix language long names detection as short name. *) mod_proxy: Worker schemes and hostnames which are too large are no longer fatal errors; it is logged and the truncated values are stored. *) CVE-2017-15715 (cve.mitre.org) core: Configure the regular expression engine to match '$' to the end of the input string only, excluding matching the end of any embedded newline characters. Behavior can be changed with new directive 'RegexDefaultOptions'. *) SECURITY: CVE-2018-1312 (cve.mitre.org) mod_auth_digest: Fix generation of nonce values to prevent replay attacks across servers using a common Digest domain. This change may cause problems if used with round robin load balancers. *) mod_proxy: Allow setting options to globally defined balancer from ProxyPass used in VirtualHost. Balancers are now merged using the new merge_balancers method which merges the balancers options. *) logresolve: Fix incorrect behavior or segfault if -c flag is used Fixes: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=823259 *) mod_remoteip: Add support for PROXY protocol (code donated by Cloudzilla). Add ability for PROXY protocol processing to be optional to donated code. See also: http://www.haproxy.org/download/1.5/doc/proxy-protocol.txt *) mod_proxy, mod_ssl: Handle SSLProxy* directives in <Proxy> sections, allowing per backend TLS configuration. *) mod_proxy_uwsgi: Add in UWSGI proxy (sub)module. *) mod_proxy_balancer,mod_slotmem_shm: Rework SHM reuse/deletion to not depend on the number of restarts (non-Unix systems) and preserve shared *) CVE-2018-1302 (cve.mitre.org) mod_http2: Potential crash w/ mod_http2. names as much as possible on configuration changes for SHMs and persisted files. *) mod_http2: obsolete code removed, no more events on beam pool destruction, discourage content encoders on http2-status response (where they do not work). *) mpm_event: Let the listener thread do its maintenance job on resources shortage. *) mpm_event: Wakeup the listener to re-enable listening sockets. *) mod_ssl: The SSLCompression directive will now give an error if used with an OpenSSL build which does not support any compression methods. *) mpm_event,worker: Mask signals for threads created by modules in child init, so that they don't receive (implicitely) the ones meant for the MPM. *) mod_md: new experimental, module for managing domains across virtual hosts, implementing the Let's Encrypt ACMEv1 protocol to signup and renew certificates. Please read the modules documentation for further instructions on how to use it. *) mod_proxy_html: skip documents shorter than 4 bytes *) core, mpm_event: Avoid a small memory leak of the scoreboard handle, for the lifetime of the connection, each time it is processed by MPM event. *) mpm_event: Update scoreboard status for KeepAlive state. *) mod_ldap: Fix a case where a full LDAP cache would continually fail to purge old entries and log AH01323. *) mpm_event: close connections not reported as handled by any module to avoid losing track of them and leaking scoreboard entries. *) core: A signal received while stopping could have crashed the main process. *) mod_ssl: support for mod_md added. *) mod_proxy_html: process parsed comments immediately. Fixes bug (seen in the wild when used with IBM's HTTPD bundle) where parsed comments may be lost. *) mod_proxy_html: introduce doctype for HTML 5 *) mod_proxy_html: fix typo-bug processing "strict" vs "transitional" HTML/XHTML. *) mpm_event: avoid a very unlikely race condition between the listener and the workers when the latter fails to add a connection to the pollset. *) core: silently ignore a not existent file path when IncludeOptional is used. *) mod_macro: fix usability of globally defined macros in .htaccess files. *) mod_rewrite, core: add the Vary header when a condition evaluates to true and the related RewriteRule is used in a Directory context (triggering an internal redirect). *) ab: Make the TLS layer aware that the underlying socket is nonblocking, and use/handle POLLOUT where needed to avoid busy IOs and recover write errors when appropriate. *) ab: Keep reading nonblocking to exhaust TCP or SSL buffers when previous read was incomplete (the SSL case can cause the next poll() to timeout since data are buffered already). *) mod_http2: avoid unnecessary data retrieval for a trace log. Allow certain information retrievals on null bucket beams where it makes sense. |
||
---|---|---|
.. | ||
files | ||
patches | ||
buildlink3.mk | ||
DESCR | ||
distinfo | ||
Makefile | ||
MESSAGE | ||
options.mk | ||
PLIST |