|
|
|
|
Changelog for httpd-debuginfo-2.0.46-75.ent.i386.rpm :
Sat Aug 8 00:00:00 2009 Joe Orton 2.0.46-75.ent - add security fix for CVE-2009-1891 (#515705) - include fix for upstream PR 39605
Thu Aug 6 00:00:00 2009 Joe Orton 2.0.46-74.ent - add security fixes for CVE-2009-2412 (#515705) - add fix to preserve Content-Length for proxied HEAD (#506016)
Tue Jun 9 00:00:00 2009 Joe Orton 2.0.46-73.ent - forcibly disable SCTP support in APR
Tue Jun 9 00:00:00 2009 Joe Orton 2.0.46-72.ent - add security fixes for CVE-2009-0023, CVE-2009-1955, and CVE-2009-1956 (apr-util) (#504562)
Tue Oct 28 23:00:00 2008 Joe Orton 2.0.46-71.ent - add security fixes for CVE-2008-2364, CVE-2008-2939 (#468837)
Mon Jan 7 23:00:00 2008 Joe Orton 2.0.46-70.ent - add security fix for CVE-2007-6388 (#427235) - add security fix for mod_proxy_ftp UTF-7 XSS (#427742)
Thu Dec 13 23:00:00 2007 Joe Orton 2.0.46-69.ent - add security fix for CVE-2007-3847 (#250759) - add security fixes for CVE-2007-4465, CVE-2007-5000 (#421601)
Sat Jun 30 00:00:00 2007 Joe Orton 2.0.46-68.ent - add security fix for CVE-2007-3304 (#246180)
Tue Jun 26 00:00:00 2007 Joe Orton 2.0.46-67.ent - rebuild
Sat Jun 23 00:00:00 2007 Joe Orton 2.0.46-66.ent - mod_cache: follow upstream max-stale handling in CVE-2007-1863 fix (#244662)
Sat Jun 23 00:00:00 2007 Joe Orton 2.0.46-65.ent - add security fixes for CVE-2007-1863 and CVE-2006-5752 (#244662)
Wed Jun 20 00:00:00 2007 Joe Orton 2.0.46-64.ent - fix ProxyErrorOverride to only affect 4xx, 5xx responses (#244639) - fix mod_proxy option inheritance (#244638)
Thu Mar 15 23:00:00 2007 Joe Orton 2.0.46-63.ent - fix Expires handling for 304 responses (#168850) - fix mod_setenvif regex optimizer (#177322) - fix mod_proxy ProxyRemoteMatch regex handling (#218317) - fix mod_ssl to send close_notify alerts (#232405) - fix mod_disk_cache content-type handling (#183880) - drop malformed Host header handling patch (#213392)
Wed Aug 2 00:00:00 2006 Joe Orton 2.0.46-61.ent - add security fix for Expect header XSS (CVE-2006-3918, #200732)
Tue Jul 25 00:00:00 2006 Joe Orton 2.0.46-60.ent - add mod_rewrite ldap scheme handling fix
Sat Jun 24 00:00:00 2006 Joe Orton 2.0.46-59.ent - rebuild
Wed Mar 22 23:00:00 2006 Joe Orton 2.0.46-57.ent - fix unixd_set_proc_mutex_perms for non-sysvsem locks (#186092)
Thu Dec 15 23:00:00 2005 Joe Orton 2.0.46-56.ent - mod_ssl: add security fix for HTTP-on-SSL-port handling (CVE-2005-3357) - mod_imap: add security fix for XSS issue (CVE-2005-3352) - worker MPM: add security fix for memory consumption DoS (CVE-2005-2970), and bug fixes for handling resource allocation failures (#173509)
Tue Oct 4 00:00:00 2005 Joe Orton 2.0.46-54.0.ent - mod_ssl: buffer request bodies for per-location renegotiation (#123585)
Thu Sep 1 00:00:00 2005 Joe Orton 2.0.52-54.ent - mod_ssl: add security fix for SSLVerifyClient (#167194, CVE CAN-2005-2700) - add security fix for byterange filter DoS (#167102, CVE CAN-2005-2728)
Thu Jul 28 00:00:00 2005 Joe Orton 2.0.46-53.ent - fix certwatch.cron
Wed Jul 27 00:00:00 2005 Joe Orton 2.0.46-52.ent - add htdbm(1) man page from upstream (#114080)
Thu Jul 21 00:00:00 2005 Joe Orton 2.0.46-51.ent - mod_ssl: add security fix for CRL overflow (CVE CAN-2005-1268)
Wed Jun 29 00:00:00 2005 Joe Orton 2.0.46-50.ent - add security fix for C-L vs T-E handling (#162244, CVE CAN-2005-2088) - suexec: fix regression in handling REDIRECT_STATUS (HSCG NOC, #161893)
Sat Jun 4 00:00:00 2005 Joe Orton 2.0.46-49.ent - mod_userdir: fix possible memory-corruption issue (upstream #34588) - apr-util: fix handling of truncated FILE buckets (#137306) - apr: remove check for R_OK access to directory when spawning new processes (upstream #30137) - certwatch: add --address, --period options (#152990)
Tue May 17 00:00:00 2005 Joe Orton 2.0.46-48.ent - avoid possible hangs during graceful restart with piped loggers (Jeff Trawick, #127981, upstream #26467) - add backport of AP_MPMQ_MPM_STATE ap_mpm_query interface - fix fd leaks when (re-)spawning piped loggers (#157832) - apr: catch errors in apr_procattr_child_ *_set to prevent segfaults
Fri Feb 4 23:00:00 2005 Joe Orton 2.0.46-46.ent - mod_include: fix off-by-one in variable expansion (upstream #32985)
Wed Jan 19 23:00:00 2005 Joe Orton 2.0.46-45.ent - mod_proxy: notice aborted client-connection (#138359) - certwatch: fix To header in warning mail (#139403) - mod_ssl: don\'t run ldconfig in %post - from upstream: * add REDIRECT_REMOTE_USER variable (André Malo, #145666)
Fri Nov 5 23:00:00 2004 Joe Orton 2.0.46-44.ent - add fix for DoS in header folding (CAN-2004-0942, #138064) - mod_disk_cache: don\'t write hop-by-hop headers to cache (#137465) - add Bojan Smojver\'s emulate_sendfile fix for >1 files per brigade - mod_ssl: fix for potential crash in some configurations (upstream #31848)
Thu Oct 7 00:00:00 2004 Joe Orton 2.0.46-43.ent - fix SSLCipherSuite bypass issue (CAN-2004-0885, Hartmut Keil)
Fri Sep 24 00:00:00 2004 Joe Orton 2.0.46-42.ent - raise RLIMIT_CORE to hard limit if CoreDumpDirectory is enabled - apr: define APR_LARGEFILE flag - log_error_core: log basename(__FILE__) file for APLOG_DEBUG - update apxs.8 man page
Thu Sep 23 00:00:00 2004 Joe Orton 2.0.46-41.ent - mod_dav_fs: also fix indirect lock handling on s390x (#132593) - mod_cgi: fix CGI bucket issues in subrequest (upstream #31247) - merge another ap_rgetline_core NUL-termination fix from 2.0.51
Tue Sep 14 00:00:00 2004 Joe Orton 2.0.46-40.ent - mod_dav_fs: security fix for indirect lock refresh (CAN-2004-0809) - mod_dav_fs: fix indirect lock handling on 64-bit platforms
Tue Sep 7 00:00:00 2004 Joe Orton 2.0.46-39.ent - add security fixes for CAN-2004-0747, CAN-2004-0786 - mod_ssl: add security fix for CAN-2004-0751 - split security fix for CAN-2004-0748 out from -sslio patch - merge ap_rgetline_core NUL-termination fixes from 2.0.5[01] - have -devel require httpd of same V-R
Tue Jul 13 00:00:00 2004 Joe Orton 2.0.46-38.ent - drop suexec minimum acceptable gid to 100 (#127667) - mod_ssl: fix for upstream #29964
Wed Jun 30 00:00:00 2004 Joe Orton 2.0.46-37.ent - add security fix for CAN-2004-0493 (Jeff Trawick)
Wed Jun 23 00:00:00 2004 Joe Orton 2.0.46-36.ent - mod_ssl: add ssl_is_https optional hook - mod_rewrite: add %{SSL:...} SSL variable lookup hook - mod_rewrite: fix %{HTTPS} variable (#120096) - mod_headers: add %{...}s SSL variable lookup hook
Wed Jun 2 00:00:00 2004 Joe Orton 2.0.46-35.ent - mod_deflate: fix memory consumption for large responses - fix handling of CGI scripts which produce a Content-Range header - merge from upstream: * fix vhost address handling (Jeff Trawick)
Tue May 25 00:00:00 2004 Joe Orton 2.0.46-34.ent - mod_cgi: updated CGI bucket patch (more #112216) - mod_ssl: security fix for overflow in FakeBasicAuth (CVE CAN-2004-0488) - docs: man page presentation fixes - mod_dav: fix to propagate executable property across COPY/MOVE - mod_dav: fix some minor 2518 compliance issues and one 2617 issue - apr: support >2Gb files in apr_file_copy() - merge from upstream: * mod_auth_digest: fix for subrequest method handling (Josh Dady)
Wed Apr 7 00:00:00 2004 Joe Orton 2.0.46-33.ent - fix SHA1 password support (#119651) - mod_autoindex: don\'t truncate output on stat() failure (#117959) - mod_ssl: fix shmcb corruption with small caches (Geoff Thorpe) - mod_ssl: fix memory leak in session cache (Madhu Mathihalli) - include the mod_ext_filter module (#120072) - mod_cgi: handle concurrent output on stderr/stdout (#112216)
Mon Mar 1 23:00:00 2004 Joe Orton 2.0.46-32.ent - improved fix for CAN-2004-0113
Thu Feb 26 23:00:00 2004 Joe Orton 2.0.46-31.ent - mod_ssl: fix memory leak, CVE CAN-2004-0113 - remove check that accept() returns fd < FD_SETSIZE (#116576)
Thu Feb 19 23:00:00 2004 Joe Orton 2.0.46-30.ent - add mod_include rewrite from 2.0.49 (André Malo)
Mon Feb 16 23:00:00 2004 Joe Orton 2.0.46-29.ent - rebuild for gcc optimisation fix on IA64 (#115328) - add fix for apr_dbm_exists() for sdbm on ppc64/s390x
Tue Feb 10 23:00:00 2004 Joe Orton 2.0.46-28.ent - add libtool symlink in /etc/httpd/build (#113720) - mod_ssl: ssl_var_lookup fixes - use system pcre to prevent conflicts with PHP (#98056) - merge from upstream: * mod_dav: streaming PROPFIND responses (Ben Sussman) * apr: add apr_file_mtime_set * apr-util: add apu-config --db-version and apu_want.h support
Tue Jan 27 23:00:00 2004 Joe Orton 2.0.46-27.ent - tighten parsing of CPP output in MMN check (#113934) - fix AP[RU]_INCLUDEDIR in config_vars.mk (#112771) - ensure that suexec is stripped and has minimal dependencies - mod_ssl: fix streaming nph- CGI scripts over SSL - mod_proxy: fix some HTTP compliance issues - drop gdbm support from apr-util due to licence incompatibility - add mod_logio - merge from upstream: * fix worker crasher, memory corruption fix (Jeff Trawick)
Wed Jan 7 23:00:00 2004 Joe Orton 2.0.46-26.ent.1 - merge from upstream: * mod_proxy: fix a memory leak (Larry Hoppi, upstream #24991) * worker: fix a misleading warning message (Jeff Trawick) * mod_ssl: fix FakeBasicAuth for subrequests (Sander Striker) * mod_expires: several bug fixes (including #113929)
Mon Nov 10 23:00:00 2003 Joe Orton 2.0.46-26.ent - include security fix for CVE CAN-2003-0542 - speed up graceful restart in prefork (#105725) - move away /var/www/html/index.html before upgrade from 1.3 (#70705) - fix for config parser to support containers without args - include mpm *.h to fix mod_fastcgi build (#108080) - mod_ssl: avoid error stack dumps during pphrase prompts - mod_ssl: restore readable error descriptions in error log - mod_proxy: fix Server header for proxied requests - mod_cgi: fix logging of script exec failure messages - mod_log_config: fix logging of timezone (upstream #23642) - mod_include: fix for r->filename handling (upstream #23836)
Fri Sep 26 00:00:00 2003 Joe Orton 2.0.46-25.ent - final migration guide updates
Thu Sep 25 00:00:00 2003 Joe Orton 2.0.46-24.ent - update migration guide
Sat Sep 20 00:00:00 2003 Joe Orton 2.0.46-23.ent - mention how to disable cronned warnings in certwatch(8) - add fix for segfaults in proxy_fixup
Wed Sep 17 00:00:00 2003 Joe Orton 2.0.46-22.ent - don\'t mention CompatEnvVars in ssl.conf - add LoadModule for suexec to default httpd.conf - avoid pathological read() behaviour in mod_disk_cache
Sat Sep 13 00:00:00 2003 Joe Orton 2.0.46-21.ent - fix cleanup of -config scripts
Sat Sep 13 00:00:00 2003 Joe Orton 2.0.46-20.ent - improve default ssl.conf (Florian La Roche, #103271) - include ap[ru]-config, provide apr{,-util}-devel (Florian, #98445)
Fri Sep 12 00:00:00 2003 Joe Orton 2.0.46-19.ent - obsolete mod_put, mod_roaming - add SSL_CLIENT_V_REMAIN to mod_ssl - tweak list syntax in man pages - bump the module magic minor for VU#379828 (Peter Bowen, #104223) - avoid split for FLUSH at end of brigade (via Peter Bowen, #104224) - fix example location of ca-bundle.crt (#99243)
Sat Sep 6 00:00:00 2003 Joe Orton 2.0.46-18.ent - fix including mod_ssl.h
Sat Aug 30 00:00:00 2003 Joe Orton 2.0.46-17.ent - add new welcome page and logo (Garrett LeSage) - mod_ssl: grammar fixes for private key prompting, fix for mod_ssl plain-HTTP-not-SSL error check (Steve Henson), CLIENT_CERT_CHAIN_ lookup fix (Jeff Trawick) - mod_log_config: fix logging 0 bytes sent in CLF (Astrid Keßler)
Fri Aug 29 00:00:00 2003 Joe Orton 2.0.46-16.ent - add ThreadGuardArea directive - trim list of installed headers - link libapr and libaprutil against libpthread - from upstream (mostly): mod_ssl I/O filter fixes - don\'t add -L/usr/lib64 to LDFLAGS
Thu Aug 28 00:00:00 2003 Joe Orton 2.0.46-15.ent - include certwatch(8) in mod_ssl package - remove ssl_mutex at startup if left from previous invocation - add trigger for upgrade from Stronghold
Wed Aug 27 00:00:00 2003 Joe Orton 2.0.46-14.ent - allow upgrade from Stronghold 4.0
Sat Aug 23 00:00:00 2003 Joe Orton 2.0.46-13.ent - enable crypto accelerator support
Fri Aug 22 00:00:00 2003 Joe Orton 2.0.46-12.ent - security fixes for CVE CAN-2003-0020, CERT VU#379828 - complete removal of Welcome page bypass (#99206) - use AI_ADDRCONFIG in getaddrinfo() calls where appropriate - from upstream: mod_deflate fixes
Tue Aug 5 00:00:00 2003 Joe Orton 2.0.46-11.ent - support httpd -t -DDUMP_CERTS to dump SSL certificates - use /dev/urandom to fix slow mod_auth_digest startup - add apr fix for race in nested mutexes - disable multilingual error docs by default (#99472) - move configuration for Welcome page to conf.d (#99206) - default Listen to use IPv4 not IPv6 if no address is specified
Thu Jul 31 00:00:00 2003 Joe Orton 2.0.46-10.ent - add fix for mod_ssl leaving libcrypto in bad state during startup - allow large (>2gb) log files on 32-bit platforms (#80603) - fix handling of -Wc, options when linking in apxs
Thu Jul 31 00:00:00 2003 Joe Orton 2.0.46-9.ent - rebuild to fix #101145
Wed Jul 30 00:00:00 2003 Joe Orton 2.0.46-8.ent - security fixes for CAN-2003-0192, CAN-2003-0253, CAN-2003-0254 - use anonymous shmem in shmcb, avoiding #80520 - use sys_siglist[] array for signal number->name mappings - disable use of IPv4-mapped IPv6 addresses - only listen on 0.0.0.0 in default config (#98916) - don\'t add eNULL cipher in default ssl.conf (#98401) - load mod_deflate in default config - from upstream: mod_include fixes; open log files read-only; AddLanguage fixes to httpd.conf
Fri Jul 4 00:00:00 2003 Joe Orton 2.0.46-7.ent - fix to link mod_ssl against distcache correctly
Wed Jun 18 00:00:00 2003 Joe Orton 2.0.46-6.ent - add distcache support (feature #87074) - update server version string - remove mod_cgid - use shmcb as default session cache in ssl.conf - fix mod_ssl.h for use in installed tree
Wed Jun 11 00:00:00 2003 Joe Orton 2.0.46-5.ent - fix apxs -q LIBTOOL, apxs -g
Wed Jun 11 00:00:00 2003 Joe Orton 2.0.46-4.ent - fix httpd.worker - remove -manual subpackage
Fri May 30 00:00:00 2003 Joe Orton 2.0.46-3.ent - updates for default httpd.conf - fix omission of manual/style in httpd-manual
Fri May 30 00:00:00 2003 Joe Orton 2.0.46-2.ent - fix libtool relink bug
Fri May 30 00:00:00 2003 Joe Orton 2.0.46-1.ent - update to 2.0.46 for RHEL; use bundled apr/apr-util again - drop experimental modules
Tue May 20 00:00:00 2003 Joe Orton 2.0.45-6 - don\'t load /usr/sbin/envvars from apxs - add fix for mod_dav_fs namespace handling - add fix for mod_dav If header etag comparison - remove irrelevant warning from mod_proxy - don\'t conflict with thttpd (#91422)
Mon May 19 00:00:00 2003 Joe Orton 2.0.45-5 - don\'t package any XML sources in httpd-manual - fix examples in default httpd.conf for enabling caching
Mon May 19 00:00:00 2003 Joe Orton 2.0.45-4 - change default charset to UTF-8 (#88964)
Fri May 16 00:00:00 2003 Joe Orton 2.0.45-3 - update httpd.conf for changes from default in 2.0.45 - include conf.d/ *.conf after loading standard modules - include LDAP and cache modules (#75370, #88277) - run buildconf in %build not %prep
Wed May 14 00:00:00 2003 Joe Orton 2.0.45-2 - have apxs always use /usr/bin/libtool
Tue May 6 00:00:00 2003 Joe Orton 2.0.45-1 - update to 2.0.45 (#82227) - use separate apr, apr-util packages (#74951) - mark logrotate file as noreplace (#85654) - mark all of /var/www/error as %config-not-noreplace - remove dates from error pages (#86474) - don\'t enable mod_cgid for worker MPM (#88819)
Thu May 1 00:00:00 2003 Elliot Lee 2.0.40-22 - headusage patch to fix build on ppc64 etc.
Wed Apr 2 00:00:00 2003 Joe Orton 2.0.40-21.1 - add security fixes for CAN-2003-0020, CAN-2003-0132, CAN-2003-0083 - add security fix for file descriptor leaks, #82142 - add bug fix for #82587
Mon Feb 24 23:00:00 2003 Joe Orton 2.0.40-21 - add security fix for CAN-2003-0020; replace non-printable characters with \'!\' when printing to error log. - disable debuginfo on IA64.
Tue Feb 11 23:00:00 2003 Joe Orton 2.0.40-20 - disable POSIX semaphores to support 2.4.18 kernel (#83324)
Wed Jan 29 23:00:00 2003 Joe Orton 2.0.40-19 - require xmlto 0.0.11 or later - fix apr_strerror on glibc2.3
Wed Jan 22 23:00:00 2003 Tim Powers 2.0.40-18 - rebuilt
Thu Jan 16 23:00:00 2003 Joe Orton 2.0.40-17 - add mod_cgid and httpd binary built with worker MPM (#75496) - allow choice of httpd binary in init script - pick appropriate CGI module based on loaded MPM in httpd.conf - source /etc/sysconfig/httpd in apachectl to get httpd choice - make \"apachectl status\" fail gracefully when links isn\'t found (#78159)
Mon Jan 13 23:00:00 2003 Joe Orton 2.0.40-16 - rebuild for OpenSSL 0.9.7
Fri Jan 3 23:00:00 2003 Joe Orton 2.0.40-15 - fix possible infinite recursion in config dir processing (#77206) - fix memory leaks in request body processing (#79282)
Thu Dec 12 23:00:00 2002 Joe Orton 2.0.40-14 - remove unstable shmht session cache from mod_ssl - get SSL libs from pkg-config if available (Nalin Dahyabhai) - stop \"apxs -a -i\" from inserting AddModule into httpd.conf (#78676)
Wed Nov 6 23:00:00 2002 Joe Orton 2.0.40-13 - fix location of installbuilddir in apxs when libdir!=/usr/lib
Wed Nov 6 23:00:00 2002 Joe Orton 2.0.40-12 - pass libdir to configure; clean up config_vars.mk - package instdso.sh, fixing apxs -i (#73428) - prevent build if upstream MMN differs from mmn macro - remove installed but unpackaged files
Thu Oct 10 00:00:00 2002 Joe Orton 2.0.40-11 - correct SERVER_NAME encoding in i18n error pages (thanks to Andre Malo)
Thu Oct 10 00:00:00 2002 Joe Orton 2.0.40-10 - fix patch for CAN-2002-0840 to also cover i18n error pages
Thu Oct 3 00:00:00 2002 Joe Orton 2.0.40-9 - security fixes for CAN-2002-0840 and CAN-2002-0843 - fix for possible mod_dav segfault for certain requests
Wed Sep 25 00:00:00 2002 Gary Benson - updates to the migration guide
Thu Sep 5 00:00:00 2002 Nalin Dahyabhai 2.0.40-8 - link httpd with libssl to avoid library loading/unloading weirdness
Wed Sep 4 00:00:00 2002 Joe Orton 2.0.40-7 - add LoadModule lines for proxy modules in httpd.conf (#73349) - fix permissions of conf/ssl. */ directories; add Makefiles for certificate management (#73352)
Tue Sep 3 00:00:00 2002 Joe Orton 2.0.40-6 - provide \"httpd-mmn\" to manage module ABI compatibility
Mon Sep 2 00:00:00 2002 Joe Orton 2.0.40-5 - fix SSL session cache (#69699) - revert addition of LDAP support to apr-util
Tue Aug 27 00:00:00 2002 Joe Orton 2.0.40-4 - set SIGXFSZ disposition to \"ignored\" (#69520) - make dummy connections to the first listener in config (#72692)
Tue Aug 27 00:00:00 2002 Joe Orton 2.0.40-3 - allow \"apachectl configtest\" on a 1.3 httpd.conf - add mod_deflate - enable LDAP support in apr-util - don\'t package everything in /var/www/error as config(noreplace)
Thu Aug 22 00:00:00 2002 Bill Nottingham 2.0.40-2 - add trigger (#68657)
Tue Aug 13 00:00:00 2002 Joe Orton 2.0.40-1 - update to 2.0.40
Thu Jul 25 00:00:00 2002 Joe Orton 2.0.36-8 - improve comment on use of UserDir in default config (#66886)
Thu Jul 11 00:00:00 2002 Joe Orton 2.0.36-7 - use /sbin/nologin as shell for apache user (#68371) - add patch from CVS to fix possible infinite loop when processing internal redirects
Thu Jun 27 00:00:00 2002 Gary Benson 2.0.36-6 - modify init script to detect 1.3.x httpd.conf\'s and direct users to the migration guide
Wed Jun 26 00:00:00 2002 Gary Benson 2.0.36-5 - patch apachectl to detect 1.3.x httpd.conf\'s and direct users to the migration guide - ship the migration guide
Sat Jun 22 00:00:00 2002 Joe Orton - move /etc/httpd2 back to /etc/httpd - add noindex.html page and poweredby logo; tweak default config to load noindex.html if no default \"/\" page is present. - add patch to prevent mutex errors on graceful restart
Sat Jun 22 00:00:00 2002 Tim Powers 2.0.36-4 - automated rebuild
Thu Jun 13 00:00:00 2002 Joe Orton 2.0.36-3 - add patch to fix SSL mutex handling
Thu Jun 13 00:00:00 2002 Joe Orton 2.0.36-2 - improved config directory patch
Tue May 21 00:00:00 2002 Joe Orton - initial build; based heavily on apache.spec and mod_ssl.spec - fixes: #65214, #58490, #57376, #61265, #65518, #58177, #57245
|
|
|