dea3475122
Changes with Apache 2.4.41 *) SECURITY: CVE-2019-10081 (cve.mitre.org) mod_http2: HTTP/2 very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client. *) SECURITY: CVE-2019-9517 (cve.mitre.org) mod_http2: a malicious client could perform a DoS attack by flooding a connection with requests and basically never reading responses on the TCP connection. Depending on h2 worker dimensioning, it was possible to block those with relatively few connections. *) SECURITY: CVE-2019-10098 (cve.mitre.org) rewrite, core: Set PCRE_DOTALL flag by default to avoid unpredictable matches and substitutions with encoded line break characters. *) SECURITY: CVE-2019-10092 (cve.mitre.org) Remove HTML-escaped URLs from canned error responses to prevent misleading text/links being displayed via crafted links. *) SECURITY: CVE-2019-10097 (cve.mitre.org) mod_remoteip: Fix stack buffer overflow and NULL pointer deference when reading the PROXY protocol header. *) SECURITY: CVE-2019-10082 (cve.mitre.org) mod_http2: Using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown. *) mod_proxy_balancer: Improve balancer-manager protection against XSS/XSRF attacks from trusted users. *) mod_session: Introduce SessionExpiryUpdateInterval which allows to configure the session/cookie expiry's update interval. *) modules/filters: Fix broken compilation when using old GCC (<4.2.x). *) mod_ssl: Fix startup failure in 2.4.40 with SSLCertificateChainFile configured for a domain managed by mod_md.
17 lines
1 KiB
Text
17 lines
1 KiB
Text
$NetBSD: distinfo,v 1.41 2019/08/15 08:03:39 adam Exp $
|
|
|
|
SHA1 (httpd-2.4.41.tar.bz2) = b46a02237f03384fa50ddbde9be62092dc23e684
|
|
RMD160 (httpd-2.4.41.tar.bz2) = ed572c262222034a699ab55f12eaebbe070cecb7
|
|
SHA512 (httpd-2.4.41.tar.bz2) = 350cc7dcd2c439e0590338fa6da3f44df44f9bb885c381e91f91b14c2f48597f6f0bbac0ea118a8a67eaa70ae7edbb769beace368643ed73f6daee44c307b335
|
|
Size (httpd-2.4.41.tar.bz2) = 7072373 bytes
|
|
SHA1 (patch-aa) = 9a66685f1d2e4710ab464beda98cbaad632aebf9
|
|
SHA1 (patch-ab) = a3edcc20b7654e0446c7d442cda1510b23e5d324
|
|
SHA1 (patch-ac) = 9f86d845df30316d22bce677a4b176f51007ba0d
|
|
SHA1 (patch-ad) = 4ba4a9c812951f533fa316e5dbf17eaab5494157
|
|
SHA1 (patch-ae) = 5bd3bf54e792bf8a2916d7e1b49b1702b02c6903
|
|
SHA1 (patch-ag) = 50c7f0fab1cb90ac573f1c47f2d37f9c2a6247e1
|
|
SHA1 (patch-ai) = d3870e46e41adc97c3fce86f9ffd224502ad6b0c
|
|
SHA1 (patch-al) = 02d9ade5aac4270182063d5ad413970c832ee911
|
|
SHA1 (patch-am) = acdf7198ae8b4353cfc70c8015a0f09de036b777
|
|
SHA1 (patch-aw) = 43cd64df886853ef7b75b91ed20183f329fcc9df
|
|
SHA1 (patch-include_ap__config.h) = 1d056e2d4db80ec97aaf755b6dd6aff69ed2cd96
|