|
|
Subscribe / Log in / New account

Fedora alert FEDORA-2014-9057 (httpd)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 19 Update: httpd-2.4.10-1.fc19
Date:  Fri, 15 Aug 2014 02:47:11 +0000
Message-ID:  <20140815024720.0CF762254E@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2014-9057 2014-08-01 05:00:34 -------------------------------------------------------------------------------- Name : httpd Product : Fedora 19 Version : 2.4.10 Release : 1.fc19 URL : http://httpd.apache.org/ Summary : Apache HTTP Server Description : The Apache HTTP Server is a powerful, efficient, and extensible web server. -------------------------------------------------------------------------------- Update Information: This update includes the latest stable release of the Apache HTTP Server, httpd 2.4.10, fixing a number of security issues. http://www.apache.org/dist/httpd/Announcement2.4.html -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 21 2014 Joe Orton <jorton@redhat.com> - 2.4.10-1 - update to 2.4.10 - expand variables in docdir example configs - create drop directory for systemd snippets (jkaluza) - use 2048-bit RSA key with SHA-256 signature in dummy certificate * Wed Apr 9 2014 Jan Kaluza <jkaluza@redhat.com> - 2.4.9-1 - update to 2.4.9 - add support for SetHandler + proxy (#1078970) - fix graceful restart using legacy actions - conflict with pre-1.5.0 APR * Mon Jan 27 2014 Jan Kaluza <jkaluza@redhat.com> - 2.4.7-1 - update to 2.4.7 (#1034071) - mod_ssl: allow SSLEngine to override Listen-based default (r1537535) - load mod_macro by default (#998452) - add README to conf.modules.d - mod_proxy_http: add possible fix for threading issues (r1534321) - core: add fix for truncated output with CGI scripts (r1530793) * Wed Jul 31 2013 Jan Kaluza <jkaluza@redhat.com> - 2.4.6-2 - revert fix for dumping vhosts twice * Mon Jul 22 2013 Joe Orton <jorton@redhat.com> - 2.4.6-1 - update to 2.4.6 - mod_ssl: use revised NPN API (r1487772) * Thu Jul 11 2013 Jan Kaluza <jkaluza@redhat.com> - 2.4.4-12 - mod_unique_id: replace use of hostname + pid with PRNG output (#976666) - apxs: mention -p option in manpage * Tue Jul 2 2013 Joe Orton <jorton@redhat.com> - 2.4.4-11 - add patch for aarch64 (Dennis Gilmore, #925558) * Mon Jul 1 2013 Joe Orton <jorton@redhat.com> - 2.4.4-10 - remove duplicate apxs man page from httpd-tools * Mon Jun 17 2013 Joe Orton <jorton@redhat.com> - 2.4.4-9 - remove zombie dbmmanage script * Fri May 31 2013 Jan Kaluza <jkaluza@redhat.com> - 2.4.4-8 - return 400 Bad Request on malformed Host header -------------------------------------------------------------------------------- References: [ 1 ] Bug #1120596 - CVE-2014-0231 httpd: mod_cgid denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1120596 [ 2 ] Bug #1120599 - CVE-2014-0117 httpd: mod_proxy denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1120599 [ 3 ] Bug #1120601 - CVE-2014-0118 httpd: mod_deflate denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1120601 [ 4 ] Bug #1120603 - CVE-2014-0226 httpd: mod_status heap-based buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1120603 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update httpd' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds