SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for apache2-mod_security2-debugsource-2.9.4-150400.3.6.1.x86_64.rpm :

* Mon Feb 13 2023 danilo.spinellaAATTsuse.com- Fix CVE-2023-24021, FILES_TMP_CONTENT sometimes lacked the complete content (CVE-2023-24021, bsc#1207379)
* fix-CVE-2023-24021.patch
* Wed Jan 25 2023 danilo.spinellaAATTsuse.com- Fix CVE-2022-48279, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall (CVE-2022-48279, bsc#1207378)
* fix-CVE-2022-48279.patch
* Mon Jul 19 2021 danilo.spinellaAATTsuse.com- Update to 2.9.4:
* Add microsec timestamp resolution to the formatted log timestamp
* Added missing Geo Countries
* Store temporaries in the request pool for regexes compiled per-request.
* Fix other usage of the global pool for request temporaries in re_operators.c
* Adds a sanity check before use ctl:ruleRemoveTargetById and ctl:ruleRemoveTargetByMsg.
* Fix the order of error_msg validation
* When the input filter finishes, check whether we returned data
* fix: care non-null terminated chunk data
* Fix for apr_global_mutex_create() crashes with mod_security
* Fix inet addr handling on 64 bit big endian systems- Run spec-cleaner- Remove if/else for older version of SUSE distribution
* Tue Feb 23 2021 pgajdosAATTsuse.com- version update to 2.9.3
* Enable optimization for large stream input by default on IIS [Issue #1299 - AATTvictorhora, AATTzimmerle]
* Allow 0 length JSON requests. [Issue #1822 - AATTallanbomsft, AATTzimmerle, AATTvictorhora, AATTmarcstern]
* Include unanmed JSON values in unnamed ARGS [Issue #1577, #1576 - AATTmarcstern, AATTvictorhora, AATTzimmerle]
* Fix buffer size for utf8toUnicode transformation [Issue #1208 - AATTkatef, AATTvictorhora]
* Fix sanitizing JSON request bodies in native audit log format [p0pr0ck5, AATTvictorhora]
* IIS: Update Wix installer to bundle a supported CRS version (3.0) [AATTvictorhora, AATTzimmerle]
* IIS: Update dependencies for Windows build [Issue #1848 - AATTvictorhora, AATThsluoyz]
* IIS: Set SecStreamInBodyInspection by default on IIS builds (#1299) [Issue #1299 - AATTvictorhora]
* IIS: Update modsecurity.conf [Issue #788 - AATTvictorhora, AATTbrianclark]
* Add sanity check for a couple malloc() and make code more resilient [Issue #979 - AATTdogbert2, AATTvictorhora, AATTzimmerl]
* Fix NetBSD build by renaming the hmac function to avoid conflicts [Issue #1241 - AATTvictorhora, AATTjoerg, AATTsevan]
* IIS: Windows build, fix duplicate YAJL dir in script [Issue #1612 - AATTallanbomsft, AATTvictorhora]
* IIS: Remove body prebuffering due to no locking in modsecProcessRequest [Issue #1917 - AATTallanbomsft, AATTvictorhora]
* Fix mpm-itk / mod_ruid2 compatibility [Issue #712 - AATTju5t , AATTderhansen, AATTmeatlayer, AATTvictorhora]
* Code cosmetics: checks if actionset is not null before use it [Issue #1556 - AATTmarcstern, AATTzimmerle, AATTvictorhora]
* Only generate SecHashKey when SecHashEngine is On [Issue #1671 - AATTdmuey, AATTmonkburger, AATTzimmerle]
* Docs: Reformat README to Markdown and update dependencies [Issue #1857 - AATThsluoyz, AATTvictorhora]
* IIS: no lock on ProcessRequest. No reload of config. [Issue #1826 - AATTallanbomsft]
* IIS: buffer request body before taking lock [Issue #1651 - AATTallanbomsft]
* good practices: Initialize variables before use it [Issue #1889 - Marc Stern]
* Let body parsers observe SecRequestBodyNoFilesLimit [Issue #1613 - AATTallanbomsft]
* potential off by one in parse_arguments [Issue #1799 - AATTtinselcity, AATTzimmerle]
* Fix utf-8 character encoding conversion [Issue #1794 - AATTtinselcity, AATTzimmerle]
* Fix ip tree lookup on netmask content [Issue #1793 - AATTtinselcity, AATTzimmerle]
* IIS: set overrideModeDefault to Allow so that individual websites can add to their web.config file [Issue #1781 - AATTdefault-kramer]
* modsecurity.conf-recommended: Fix spelling [Issue #1721 - AATTpadraigdoran]
* build: fix when multiple lines for curl version [Issue #1771 - AATTArtistan]
* Fix arabic charset in unicode_mapping file [Issue #1619 - AATTalaa-ahmed-a]
* Optionally preallocates memory when SecStreamInBodyInspection is on [Issue #1366 - AATTallanbomsft, AATTzimmerle]
* Fixed typo in build_yajl.bat [Issue #1366 - AATTallanbomsft]
* Fixes SecConnWriteStateLimit [Issue #1545 - AATTnicjansma]
* Added \"empy chunk\" check [Issue #1347, #1446 - AATTgravagli, AATTbostrt, AATTzimmerle]
* Add capture action to AATTdetectXSS operator [Issue #1488, #1482 - AATTvictorhora]
* Fix for wildcard operator when loading conf files on Nginx / IIS [Issue #1486, #1285 - AATTvictorhora and AATTthierry-f-78]
* Set of fixies to make windows build workable with the buildbots [Commit 94fe3 - AATTzimmerle]
* Uses LOG_NO_STOPWATCH instead of DLOG_NO_STOPWATCH [Issue #1510 - AATTmarcstern]
* Adds missing headers [Issue #1454 - AATTdevnexen]- modified patches % modsecurity-fixes.patch (fix crash caused by our patch) [bsc#1180830]- added patches + modsecurity-2.9.3-input_filtering_errors.patch [bsc#1180830]
* Wed Feb 12 2020 pgajdosAATTsuse.com- removing %apache_test_
* macros, do not test module just by loading the module
* Fri Dec 29 2017 jengelhAATTinai.de- Trim advertisement and filler wording from descriptions.
* Wed Dec 20 2017 pgajdosAATTsuse.com- fix build for SLE_11_SP4: BuildRoot and %deffattr have to be present
* Mon Oct 02 2017 kstreitovaAATTsuse.com- update to 2.9.2
* release notes https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.2
* refresh apache2-mod_security2-no_rpath.diff
* remove apache2-mod_security2-lua-5.3.patch that was applied upstream- remove outdated html pages and diagram (they can be accessed online at https://github.com/SpiderLabs/ModSecurity/wiki)
* Reference-Manual.html.bz2
* ModSecurity-Frequently-Asked-Questions-FAQ.html.bz2
* modsecurity_diagram_apache_request_cycle.jpg- don\'t pack the whole doc directory as it contains also Makefiles or doxygen configuration files- disable mlogc as we don\'t pack it and it also can\'t be built for curl <=7.34- add basic and regression test suite (but disabled for now)
* add apache2-mod_security2_tests_conf.patch for apache2 configuration file used for tests that was trying to load mpm_worker_module (it\'s static for our apache2 package)
* add \"BuildRequires: perl-libwww-perl\" needed for the test suite
* Wed Jun 21 2017 dimstarAATTopensuse.org- Update modsecurity-fixes.patch: additionally include netdb.h in order to have gethostbyname defined.
* Thu Mar 23 2017 kstreitovaAATTsuse.com- cleanup with spec-cleaner
* Wed Jul 29 2015 pgajdosAATTsuse.com- fix build for lua 5.3 + apache2-mod_security2-lua-5.3.patch
* Thu Jul 16 2015 pgajdosAATTsuse.com- Requries: %{apache_suse_maintenance_mmn} This will pull this module to the update (in released distribution) when apache maintainer thinks it is good (due api/abi changes).
* Mon Mar 02 2015 tchvatalAATTsuse.com- Remove useless comment lines/whitespace
* Tue Feb 24 2015 crrodriguezAATTopensuse.org- spec, build: Respect optflags- spec: buildrequire pkgconfig- modsecurity-fixes.patch: mod_security fails at:
* building with optflags enabled due to undefined behaviour and implicit declarations.
* It abuses it apr_allocator api, creating one allocator per request and then destroying it, flooding the system with mmap() , munmap requests, this is particularly nasty with threaded mpms. it should instead use the allocator from the request pool.
* Sat Feb 14 2015 thomas.wormAATTsicsec.de- Raised to version 2.9.0- Updated patch: apache2-mod_security2-no_rpath.diff (adapted lines)
* Mon Nov 03 2014 pgajdosAATTsuse.com- call spec-cleaner- use apache rpm macros
 
ICM