APACHE 2.0 STATUS: -*-text-*-
-Last modified at [$Date: 2004/06/06 12:37:56 $]
+Last modified at [$Date: 2004/06/06 12:55:44 $]
Release:
*) mod_ssl: Fix buffer overflow in FakeBasicAuth support (CVE CAN-2004-0488)
http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_kernel.c?r1=1.105&r2=1.106
- +1: jorton, nd
+ +1: jorton, nd, trawick
*) mod_ssl: Remove some unused functions (after CAN-2004-0488 fix is applied)
http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_util.c?r1=1.46&r2=1.47
+1: jorton, nd
+ trawick: need changes to mod_ssl.h to remove prototypes for those removed functions
*) mod_ssl: Fix a GCC strict-aliasing warning.
http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_config.c?r1=1.90&r2=1.91
- +1: jorton, nd
+ +1: jorton, nd, trawick
*) mod_ssl: Cleanups and fixes for mod_ssl logging.
http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_init.c?r1=1.124&r2=1.125
http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_log.c?r1=1.31&r2=1.28
- +1: jorton, nd
+ +1: jorton, nd, trawick
*) Enable the option to support anonymous shared memory in mod_ldap.
This makes the cache work on Linux again.