ChangeLog for: 2011-05-13 21:30:07
l/apr-1.4.4-x86_64-1.txz: Upgraded.
This fixes a possible denial of service due to an unconstrained, recursive
invocation of apr_fnmatch(). This function has been reimplemented using a
non-recursive algorithm. Thanks to William Rowe.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0419
(* Security fix *)
l/apr-util-1.3.11-x86_64-1.txz: Upgraded.
n/httpd-2.2.18-x86_64-1.txz: Upgraded.
This is a bug fix release, but since the upgrades to apr/apr-util require at
least an httpd recompile we opted to upgrade to the newest httpd.