From: Eric Covener Date: Mon, 7 Jul 2025 15:46:03 +0000 (+0000) Subject: Post 2.4.64-rc2 tag updates X-Git-Tag: 2.4.64-rc2-candidate^0 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=fa05a9fb0852cbe456c6b179903eaa5ee7759456;p=thirdparty%2Fapache%2Fhttpd.git Post 2.4.64-rc2 tag updates git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/tags/2.4.64-rc2-candidate@1927058 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/docs/manual/mod/core.html.en b/docs/manual/mod/core.html.en index 682f9a1d40..9a01933917 100644 --- a/docs/manual/mod/core.html.en +++ b/docs/manual/mod/core.html.en @@ -5022,8 +5022,12 @@ certain events before failing a request

Security

-

UNC paths accessed outside of request processing, such as during startup, - are not necessarily checked against the hosts configured with this directive.

+

The values specified by this directive are only checked by some + components of the server, prior to accessing filesystem paths that + may be inadvertently derived from untrusted inputs.

+

Windows systems should be isolated at the network layer from + making outbound SMB/NTLM calls to unexpected destinations as a + more comprehensive and pre-emptive measure.

Directive Ordering

diff --git a/docs/manual/mod/core.html.fr.utf8 b/docs/manual/mod/core.html.fr.utf8 index a408a451ad..d8f8f89b31 100644 --- a/docs/manual/mod/core.html.fr.utf8 +++ b/docs/manual/mod/core.html.fr.utf8 @@ -33,6 +33,8 @@  ja  |  tr 

+
Cette traduction peut être périmée. Vérifiez la version + anglaise pour les changements récents.
Description:Fonctionnalités de base du serveur HTTP Apache toujours disponibles
Statut:Noyau httpd
diff --git a/docs/manual/mod/core.xml.de b/docs/manual/mod/core.xml.de index 160f199bd4..07c21ef0f7 100644 --- a/docs/manual/mod/core.xml.de +++ b/docs/manual/mod/core.xml.de @@ -1,7 +1,7 @@ - + + + diff --git a/docs/manual/mod/core.xml.ja b/docs/manual/mod/core.xml.ja index 1021ced940..4820e3b66c 100644 --- a/docs/manual/mod/core.xml.ja +++ b/docs/manual/mod/core.xml.ja @@ -1,7 +1,7 @@ - + +