トップ  >  Linux14歩  >  2014-03-29 httpdのupdate
20140329 httpd-2.2.27にupdateしました


--- httpd2226/conf/original/extra/httpd-manual.conf	2013-12-05 06:22:48.465804444 +0900
+++ httpd2227/conf/original/extra/httpd-manual.conf	2014-03-28 16:14:13.094578739 +0900
@@ -20,7 +20,7 @@ AliasMatch ^/manual(?:/(?:de|en|es|fr|ja
     # .tr is text/troff in mime.types!
-        ForceType text/html
+        ForceType "text/html; charset=utf-8"
     SetEnvIf Request_URI ^/manual/(de|en|es|fr|ja|ko|pt-br|ru|tr)/ prefer-language=$1

Changes with Apache 2.2.27

*) SECURITY: CVE-2014-0098 (cve.mitre.org)
   Clean up cookie logging with fewer redundant string parsing passes.
   Log only cookies with a value assignment. Prevents segfaults when
   logging truncated cookies.
   [William Rowe, Ruediger Pluem, Jim Jagielski]

*) SECURITY: CVE-2013-6438 (cve.mitre.org)
   mod_dav: Keep track of length of cdata properly when removing
   leading spaces. Eliminates a potential denial of service from
   specifically crafted DAV WRITE requests
   [Amin Tora <Amin.Tora neustar.biz>]

*) core: draft-ietf-httpbis-p1-messaging-23 corrections regarding
   TE/CL conflicts. [Yann Ylavic <ylavic.dev gmail com>, Jim Jagielski]

*) mod_proxy_http: Core dumped under high load. PR 50335.
   [Jan Kaluza <jkaluza redhat.com>]

*) proxy_util: NULL terminate the right buffer in 'send_http_connect'.
   [Christophe Jaillet]

*) mod_proxy: Remove (never documented) <Proxy ~ wildcard-url> syntax which
   is equivalent to <ProxyMatch wildcard-url>. [Christophe Jaillet]

*) mod_ldap: Fix a potential memory leak or corruption.  PR 54936.
   [Zhenbo Xu <zhenbo1987 gmail com>]

*) mod_ssl: Do not perform SNI / Host header comparison in case of a
   forward proxy request. [Ruediger Pluem]

*) mod_rewrite: Add mod_rewrite.h to the headers installed on Windows. 
   PR46679 [Bob Ionescu]
