From: Eric Covener Date: Fri, 9 Dec 2016 13:58:30 +0000 (+0000) Subject: backported X-Git-Tag: 2.5.0-alpha~931 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=cc996f2bf3cb2fdb52a699950631944e71861364;p=thirdparty%2Fapache%2Fhttpd.git backported git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1773396 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/CHANGES b/CHANGES index 517ed5abbb5..f50ca641708 100644 --- a/CHANGES +++ b/CHANGES @@ -4,16 +4,6 @@ Changes with Apache 2.5.0 *) core: Drop Content-Length header and message-body from HTTP 204 responses. PR 51350 [Luca Toscano] - *) SECURITY: CVE-2016-2161 (cve.mitre.org) - mod_auth_digest: Prevent segfaults during client entry allocation when the - shared memory space is exhausted. [Maksim Malyutin , - Eric Covener, Jacob Champion] - - *) SECURITY: CVE-2016-0736 (cve.mitre.org) - mod_session_crypto: Authenticate the session data/cookie with a - MAC (SipHash) to prevent deciphering or tampering with a padding - oracle attack. [Yann Ylavic, Colm MacCarthaigh] - *) mod_lua: Fix default value of LuaInherit directive. It should be 'parent-first' instead of 'none', as per documentation. PR 60419 [Christophe Jaillet]