From 63453725b4c98d922ff6ca6fe0a392de2850fbec Mon Sep 17 00:00:00 2001 From: Eric Covener Date: Tue, 6 Dec 2016 13:54:05 +0000 Subject: [PATCH] format CVE entries git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1772895 13f79535-47bb-0310-9956-ffa450edef68 --- CHANGES | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index 9c4ce2ed9c..23ba1c9758 100644 --- a/CHANGES +++ b/CHANGES @@ -2,12 +2,15 @@ Changes with Apache 2.4.24 - *) mod_http2: CVE-2016-8740: Mitigate DoS memory exhaustion via endless + + *) SECURITY: CVE-2016-8740 (cve.mitre.org) + mod_http2: Mitigate DoS memory exhaustion via endless CONTINUATION frames. [Naveen Tiwari and CDF/SEFCOM at Arizona State University, Stefan Eissing] - *) core: CVE-2016-5387: Mitigate [f]cgi "httpoxy" issues. + *) SECURITY: CVE-2016-5387 (cve.mitre.org) + core: Mitigate [f]cgi "httpoxy" issues. [Dominic Scheirlinck , Yann Ylavic] *) Enforce http request grammer corresponding to RFC7230 for request lines -- 2.40.0