From e35f03b310db47a9a9aa767c6e29e0d9d20d78c1 Mon Sep 17 00:00:00 2001 From: Geoffrey Young Date: Tue, 21 Sep 2004 13:23:47 +0000 Subject: [PATCH] SECURITY: CAN-2004-0811 officially part of 2.0.52 git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@105228 13f79535-47bb-0310-9956-ffa450edef68 --- CHANGES | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/CHANGES b/CHANGES index ed6faf0e16..8d5f8c50c4 100644 --- a/CHANGES +++ b/CHANGES @@ -2,11 +2,6 @@ Changes with Apache 2.1.0-dev [Remove entries to the current 2.0 section below, when backported] - *) SECURITY: CAN-2004-0811 (cve.mitre.org) - Fix merging of the Satisfy directive, which was applied to - the surrounding context and could allow access despite configured - authentication. PR 31315. [Rici Lake ] - *) Fix the global mutex crash when the global mutex is never allocated due to disabled/empty caches. [Jess Holle ] @@ -419,6 +414,11 @@ Changes with Apache 2.1.0-dev Changes with Apache 2.0.52 + *) SECURITY: CAN-2004-0811 (cve.mitre.org) + Fix merging of the Satisfy directive, which was applied to + the surrounding context and could allow access despite configured + authentication. PR 31315. [Rici Lake ] + *) Fix the handling of URIs containing %2F when AllowEncodedSlashes is enabled. Previously, such urls would still be rejected. [Jeff Trawick, Bill Stoddard] -- 2.40.0