Mailing List Archive

svn commit: r68309 - /dev/httpd/ /release/httpd/
Author: covener
Date: Thu Apr 4 13:33:57 2024
New Revision: 68309

Log:
Add release httpd-2.4.59 from voted 2.4.59-rc1

Added:
release/httpd/CHANGES_2.4.59
- copied unchanged from r68308, dev/httpd/CHANGES_2.4.59
release/httpd/httpd-2.4.59.tar.bz2
- copied unchanged from r68308, dev/httpd/httpd-2.4.59-rc1.tar.bz2
release/httpd/httpd-2.4.59.tar.bz2.asc
- copied unchanged from r68308, dev/httpd/httpd-2.4.59-rc1.tar.bz2.asc
release/httpd/httpd-2.4.59.tar.bz2.sha256
- copied, changed from r68308, dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha256
release/httpd/httpd-2.4.59.tar.bz2.sha512
- copied, changed from r68308, dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha512
release/httpd/httpd-2.4.59.tar.gz
- copied unchanged from r68308, dev/httpd/httpd-2.4.59-rc1.tar.gz
release/httpd/httpd-2.4.59.tar.gz.asc
- copied unchanged from r68308, dev/httpd/httpd-2.4.59-rc1.tar.gz.asc
release/httpd/httpd-2.4.59.tar.gz.sha256
- copied, changed from r68308, dev/httpd/httpd-2.4.59-rc1.tar.gz.sha256
release/httpd/httpd-2.4.59.tar.gz.sha512
- copied, changed from r68308, dev/httpd/httpd-2.4.59-rc1.tar.gz.sha512
Removed:
dev/httpd/CHANGES_2.4
dev/httpd/CHANGES_2.4.59
dev/httpd/httpd-2.4.59-rc1-deps.tar.bz2
dev/httpd/httpd-2.4.59-rc1-deps.tar.bz2.asc
dev/httpd/httpd-2.4.59-rc1-deps.tar.bz2.sha256
dev/httpd/httpd-2.4.59-rc1-deps.tar.bz2.sha512
dev/httpd/httpd-2.4.59-rc1-deps.tar.gz
dev/httpd/httpd-2.4.59-rc1-deps.tar.gz.asc
dev/httpd/httpd-2.4.59-rc1-deps.tar.gz.sha256
dev/httpd/httpd-2.4.59-rc1-deps.tar.gz.sha512
dev/httpd/httpd-2.4.59-rc1.tar.bz2
dev/httpd/httpd-2.4.59-rc1.tar.bz2.asc
dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha256
dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha512
dev/httpd/httpd-2.4.59-rc1.tar.gz
dev/httpd/httpd-2.4.59-rc1.tar.gz.asc
dev/httpd/httpd-2.4.59-rc1.tar.gz.sha256
dev/httpd/httpd-2.4.59-rc1.tar.gz.sha512
Modified:
release/httpd/Announcement2.4.html
release/httpd/Announcement2.4.txt
release/httpd/CHANGES_2.4

Modified: release/httpd/Announcement2.4.html
==============================================================================
--- release/httpd/Announcement2.4.html (original)
+++ release/httpd/Announcement2.4.html Thu Apr 4 13:33:57 2024
@@ -49,15 +49,15 @@
<div class="banner"></div>

<h1>
- Apache HTTP Server 2.4.58 Released
+ Apache HTTP Server 2.4.59 Released
</h1>
<p>
- October 19, 2023
+ April 04, 2024
</p>
<p>
The Apache Software Foundation and the Apache HTTP Server Project are
pleased to <a href="https://www.apache.org/dist/httpd/Announcement2.4.html">announce</a>
- the release of version 2.4.58 of the Apache
+ the release of version 2.4.59 of the Apache
HTTP Server ("Apache"). This version of Apache is our latest GA
release of the new generation 2.4.x branch of Apache HTTPD and
represents fifteen years of innovation by the project, and is
@@ -69,7 +69,7 @@
encourage users of all prior versions to upgrade.
</p>
<p>
- Apache HTTP Server 2.4.58 is available for download from:
+ Apache HTTP Server 2.4.59 is available for download from:
</p>
<dl>
<dd><a href="https://httpd.apache.org/download.cgi"
@@ -77,7 +77,7 @@
</dl>
<p>
Please see the <a href="./CHANGES_2.4">CHANGES_2.4</a> file, linked from the download page, for a
- full list of changes. A condensed list, <a href="./CHANGES_2.4.58">CHANGES_2.4.58</a> includes only
+ full list of changes. A condensed list, <a href="./CHANGES_2.4.59">CHANGES_2.4.59</a> includes only
those changes introduced since the prior 2.4 release. A summary of all
of the security vulnerabilities addressed in this and earlier releases
is available:

Modified: release/httpd/Announcement2.4.txt
==============================================================================
--- release/httpd/Announcement2.4.txt (original)
+++ release/httpd/Announcement2.4.txt Thu Apr 4 13:33:57 2024
@@ -1,9 +1,9 @@
- Apache HTTP Server 2.4.58 Released
+ Apache HTTP Server 2.4.59 Released

- October 19, 2023
+ April 04, 2024

The Apache Software Foundation and the Apache HTTP Server Project
- are pleased to announce the release of version 2.4.58 of the Apache
+ are pleased to announce the release of version 2.4.59 of the Apache
HTTP Server ("Apache"). This version of Apache is our latest GA
release of the new generation 2.4.x branch of Apache HTTPD and
represents fifteen years of innovation by the project, and is
@@ -13,7 +13,7 @@
We consider this release to be the best version of Apache available, and
encourage users of all prior versions to upgrade.

- Apache HTTP Server 2.4.58 is available for download from:
+ Apache HTTP Server 2.4.59 is available for download from:

https://httpd.apache.org/download.cgi

@@ -24,7 +24,7 @@
https://httpd.apache.org/docs/trunk/new_features_2_4.html

Please see the CHANGES_2.4 file, linked from the download page, for a
- full list of changes. A condensed list, CHANGES_2.4.58 includes only
+ full list of changes. A condensed list, CHANGES_2.4.59 includes only
those changes introduced since the prior 2.4 release. A summary of all
of the security vulnerabilities addressed in this and earlier releases
is available:

Modified: release/httpd/CHANGES_2.4
==============================================================================
--- release/httpd/CHANGES_2.4 (original)
+++ release/httpd/CHANGES_2.4 Thu Apr 4 13:33:57 2024
@@ -1,4 +1,84 @@
-*- coding: utf-8 -*-
+Changes with Apache 2.4.59
+
+ *) mod_deflate: Fixes and better logging for handling various
+ error and edge cases. [.Eric Covener, Yann Ylavic, Joe Orton,
+ Eric Norris <enorris etsy.com>]
+
+ *) Add CGIScriptTimeout to mod_cgi. [Eric Covener]
+
+ *) mod_xml2enc: Tolerate libxml2 2.12.0 and later. PR 68610
+ [ttachi <tachihara AT hotmail.com>]
+
+ *) mod_slotmem_shm: Use ap_os_is_path_absolute() to make it portable.
+ [Jean-Frederic Clere]
+
+ *) mod_ssl: Use OpenSSL-standard functions to assemble CA
+ name lists for SSLCACertificatePath/SSLCADNRequestPath.
+ Names will now be consistently sorted. PR 61574.
+ [Joe Orton]
+
+ *) mod_xml2enc: Update check to accept any text/ media type
+ or any XML media type per RFC 7303, avoiding
+ corruption of Microsoft OOXML formats. PR 64339.
+ [Joseph Heenan <joseph.heenan fintechlabs.io>, Joe Orton]
+
+ *) mod_http2: v2.0.26 with the following fixes:
+ - Fixed `Date` header on requests upgraded from HTTP/1.1 (h2c). Fixes
+ <https://github.com/icing/mod_h2/issues/272>.
+ - Fixed small memory leak in h2 header bucket free. Thanks to
+ Michael Kaufmann for finding this and providing the fix.
+
+ *) htcacheclean: In -a/-A mode, list all files per subdirectory
+ rather than only one. PR 65091.
+ [Artem Egorenkov <aegorenkov.91 gmail.com>]
+
+ *) mod_ssl: SSLProxyMachineCertificateFile/Path may reference files
+ which include CA certificates; those CA certs are treated as if
+ configured with SSLProxyMachineCertificateChainFile. [Joe Orton]
+
+ *) htpasswd, htdbm, dbmmanage: Update help&docs to refer to
+ "hashing", rather than "encrypting" passwords.
+ [Michele Preziuso <mpreziuso kaosdynamics.com>]
+
+ *) mod_ssl: Fix build with LibreSSL 2.0.7+. PR 64047.
+ [Giovanni Bechis, Yann Ylavic]
+
+ *) htpasswd: Add support for passwords using SHA-2. [Joe Orton,
+ Yann Ylavic]
+
+ *) core: Allow mod_env to override system environment vars. [Joe Orton]
+
+ *) Allow mod_dav_fs to tolerate race conditions between PROPFIND and an
+ operation which removes a directory/file between apr_dir_read() and
+ apr_stat(). Current behaviour is to abort the connection which seems
+ inferior to tolerating (and logging) the error. [Joe Orton]
+
+ *) mod_ldap: HTML-escape data in the ldap-status handler.
+ [Eric Covener, Chamal De Silva]
+
+ *) mod_ssl: Disable the OpenSSL ENGINE API when OPENSSL_NO_ENGINE is set.
+ Allow for "SSLCryptoDevice builtin" if the ENGINE API is not available,
+ notably with OpenSSL >= 3. PR 68080. [Yann Ylavic, Joe Orton]
+
+ *) mod_ssl: Improve compatibility with OpenSSL 3, fix build warnings about
+ deprecated ENGINE_ API, honor OPENSSL_API_COMPAT setting while defaulting
+ to compatibitily with version 1.1.1 (including ENGINEs / SSLCryptoDevice).
+ [Yann Ylavic]
+
+ *) mod_ssl: release memory to the OS when needed. [Giovanni Bechis]
+
+ *) mod_proxy: Ignore (and warn about) enablereuse=on for ProxyPassMatch when
+ some dollar substitution (backreference) happens in the hostname or port
+ part of the URL. [Yann Ylavic]
+
+ *) mod_proxy: Allow to set a TTL for how long DNS resolutions to backend
+ systems are cached. [Yann Ylavic]
+
+ *) mod_proxy: Add optional third argument for ProxyRemote, which
+ configures Basic authentication credentials to pass to the remote
+ proxy. PR 37355. [Joe Orton]
+
Changes with Apache 2.4.58

*) SECURITY: CVE-2023-45802: Apache HTTP Server: HTTP/2 stream

Copied: release/httpd/httpd-2.4.59.tar.bz2.sha256 (from r68308, dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha256)
==============================================================================
--- dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha256 (original)
+++ release/httpd/httpd-2.4.59.tar.bz2.sha256 Thu Apr 4 13:33:57 2024
@@ -1 +1 @@
-ec51501ec480284ff52f637258135d333230a7d229c3afa6f6c2f9040e321323 *httpd-2.4.59-rc1.tar.bz2
+ec51501ec480284ff52f637258135d333230a7d229c3afa6f6c2f9040e321323 *httpd-2.4.59.tar.bz2

Copied: release/httpd/httpd-2.4.59.tar.bz2.sha512 (from r68308, dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha512)
==============================================================================
--- dev/httpd/httpd-2.4.59-rc1.tar.bz2.sha512 (original)
+++ release/httpd/httpd-2.4.59.tar.bz2.sha512 Thu Apr 4 13:33:57 2024
@@ -1 +1 @@
-209da0bbac5e2564d4590302515b35495be6402273ff4024aa93e85e44554c95e053201d606383936425a41e1b5b97e6b40055dcbb385eb691a5029a6f3158c2 *httpd-2.4.59-rc1.tar.bz2
+209da0bbac5e2564d4590302515b35495be6402273ff4024aa93e85e44554c95e053201d606383936425a41e1b5b97e6b40055dcbb385eb691a5029a6f3158c2 *httpd-2.4.59.tar.bz2

Copied: release/httpd/httpd-2.4.59.tar.gz.sha256 (from r68308, dev/httpd/httpd-2.4.59-rc1.tar.gz.sha256)
==============================================================================
--- dev/httpd/httpd-2.4.59-rc1.tar.gz.sha256 (original)
+++ release/httpd/httpd-2.4.59.tar.gz.sha256 Thu Apr 4 13:33:57 2024
@@ -1 +1 @@
-e4ec4ce12c6c8f5a794dc2263d126cb1d6ef667f034c4678ec945d61286e8b0f *httpd-2.4.59-rc1.tar.gz
+e4ec4ce12c6c8f5a794dc2263d126cb1d6ef667f034c4678ec945d61286e8b0f *httpd-2.4.59.tar.gz

Copied: release/httpd/httpd-2.4.59.tar.gz.sha512 (from r68308, dev/httpd/httpd-2.4.59-rc1.tar.gz.sha512)
==============================================================================
--- dev/httpd/httpd-2.4.59-rc1.tar.gz.sha512 (original)
+++ release/httpd/httpd-2.4.59.tar.gz.sha512 Thu Apr 4 13:33:57 2024
@@ -1 +1 @@
-baa96a7c9bba48f758ca9b3e3d63f0c65db960653618109d4d7bcbf3d4776d1d51453beb65e5af57655f0b1cfb88913842bc3a117fe7acc754ddb43d4524bc82 *httpd-2.4.59-rc1.tar.gz
+baa96a7c9bba48f758ca9b3e3d63f0c65db960653618109d4d7bcbf3d4776d1d51453beb65e5af57655f0b1cfb88913842bc3a117fe7acc754ddb43d4524bc82 *httpd-2.4.59.tar.gz