tree, and other minor MPE tweaks.
[Mark Bixby <mark_bixby@hp.com>]
- *) Tighten up the syntax checking of Host: headers to fix a
+ *) Security: Tighten up the syntax checking of Host: headers to fix a
security bug in some mass virtual hosting configurations
that can allow a remote attacker to retrieve some files
on the system that should be inaccessible. [Tony Finch]
SHA1 and plaintext password encodings. Make feature tests a
bit more flexible. [William Rowe]
- *) Fix a security problem that affects some configurations of
+ *) Security: CVE-2000-0913
+ Fix a security problem that affects some configurations of
mod_rewrite. If the result of a RewriteRule is a filename that
contains expansion specifiers, especially regexp backreferences
$0..$9 and %0..%9, then it may have been possible for an attacker