Slackwarearm-14.0 ChangeLog (2014-07-27)

Sun Jul 27 17:47:38 UTC 2014

  • patches/packages/httpd-2.4.10-arm-1_slack14.0.txz
    This update fixes the following security issues:
    *) SECURITY: CVE-2014-0117 (
    mod_proxy: Fix crash in Connection header handling which
    allowed a denial of service attack against a reverse proxy
    with a threaded MPM. [Ben Reser]
    *) SECURITY: CVE-2014-0118 (
    mod_deflate: The DEFLATE input filter (inflates request bodies) now
    limits the length and compression ratio of inflated request bodies to
    avoid denial of sevice via highly compressed bodies. See directives
    DeflateInflateLimitRequestBody, DeflateInflateRatioLimit,
    and DeflateInflateRatioBurst. [Yann Ylavic, Eric Covener]
    *) SECURITY: CVE-2014-0226 (
    Fix a race condition in scoreboard handling, which could lead to
    a heap buffer overflow. [Joe Orton, Eric Covener]
    *) SECURITY: CVE-2014-0231 (
    mod_cgid: Fix a denial of service against CGI scripts that do
    not consume stdin that could lead to lingering HTTPD child processes
    filling up the scoreboard and eventually hanging the server. By
    default, the client I/O timeout (Timeout directive) now applies to
    communication with scripts. The CGIDScriptTimeout directive can be
    used to set a different timeout for communication with scripts.
    [Rainer Jung, Eric Covener, Yann Ylavic]
    For more information, see:
    (* Security fix *)
