changelog_14.2
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
changelog_14.2 [2021/09/21 19:48] – [2021-09-17] connie | changelog_14.2 [2021/10/10 04:58] – [2021=10-05] connie | ||
---|---|---|---|
Line 2: | Line 2: | ||
Slackware upstream ChangeLog entries are courtesy of Patrick Volkerding. | Slackware upstream ChangeLog entries are courtesy of Patrick Volkerding. | ||
+ | |||
+ | ==== 2021-10-10 ==== | ||
+ | |||
+ | **httpd-2.4.51**: | ||
+ | SECURITY: CVE-2021-42013: | ||
+ | Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete | ||
+ | fix of CVE-2021-41773) (cve.mitre.org) | ||
+ | It was found that the fix for CVE-2021-41773 in Apache HTTP | ||
+ | Server 2.4.50 was insufficient. | ||
+ | traversal attack to map URLs to files outside the directories | ||
+ | configured by Alias-like directives. | ||
+ | If files outside of these directories are not protected by the | ||
+ | usual default configuration " | ||
+ | can succeed. If CGI scripts are also enabled for these aliased | ||
+ | pathes, this could allow for remote code execution. | ||
+ | This issue only affects Apache 2.4.49 and Apache 2.4.50 and not | ||
+ | earlier versions. | ||
+ | Credits: Reported by Juan Escobar from Dreamlab Technologies, | ||
+ | Fernando MuA+-oz from NULL Life CTF Team, and Shungo Kumasaka | ||
+ | For more information, | ||
+ | * https:// | ||
+ | (**Security fix**) | ||
+ | |||
+ | ==== 2021-10-05 ==== | ||
+ | |||
+ | **httpd-2.4.50**: | ||
+ | This release contains security fixes and improvements. | ||
+ | Fixed null pointer dereference in h2 fuzzing. | ||
+ | Fixed path traversal and file disclosure vulnerability. | ||
+ | For more information, | ||
+ | * https:// | ||
+ | * https:// | ||
+ | (**Security fix**) | ||
+ | |||
+ | **ca-certificates-20211005** | ||
+ | This update provides the latest CA certificates to check for the | ||
+ | authenticity of SSL connections. | ||
+ | Don't install / | ||
+ | generated list that will just end up suffering a mismatch with the files | ||
+ | included in the package. Thanks to Weber Kai. | ||
+ | |||
+ | **glibc-zoneinfo-2021** | ||
+ | This package provides the latest timezone updates. | ||
==== 2021-09-21 ==== | ==== 2021-09-21 ==== |
changelog_14.2.txt · Last modified: 2023/12/23 13:40 by connie