]> git.ipfire.org Git - thirdparty/apache/httpd.git/commitdiff
* Remove the word SECURITY to address Joe's and Bill's concern that this would
authorRuediger Pluem <rpluem@apache.org>
Thu, 20 Jul 2006 22:04:13 +0000 (22:04 +0000)
committerRuediger Pluem <rpluem@apache.org>
Thu, 20 Jul 2006 22:04:13 +0000 (22:04 +0000)
  imply that FollowSymLinks and SymLinksIfOwnerMatch are security features.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@424084 13f79535-47bb-0310-9956-ffa450edef68

CHANGES

diff --git a/CHANGES b/CHANGES
index c853a8fddbbe12e77041b137886ac3a18a9e572f..303fe87263315ac61a9798c4dd4ee0e9149985c8 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -2,8 +2,7 @@
 Changes with Apache 2.3.0
   [Remove entries to the current 2.0 and 2.2 section below, when backported]
 
-  *) SECURITY:
-     core: Do not allow internal redirects like the DirectoryIndex of mod_dir
+  *) core: Do not allow internal redirects like the DirectoryIndex of mod_dir
      to circumvent the symbolic link checks imposed by FollowSymLinks and
      SymLinksIfOwnerMatch. [Nick Kew, Ruediger Pluem, William Rowe]