From: Rainer Jung Date: Thu, 16 Jan 2025 17:56:33 +0000 (+0000) Subject: Space police. X-Git-Tag: 2.4.63-candidate~18 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=5e628e7a060819b68acac559cd9cb557b1b52d38;p=thirdparty%2Fapache%2Fhttpd.git Space police. git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1923172 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/CHANGES b/CHANGES index e36931136c..9214d43bcd 100644 --- a/CHANGES +++ b/CHANGES @@ -98,7 +98,7 @@ Changes with Apache 2.4.62 *) SECURITY: CVE-2024-40725: Apache HTTP Server: source code disclosure with handlers configured via AddType (cve.mitre.org) - A partial fix for CVE-2024-39884 in the core of Apache HTTP + A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly,