current/doc/source changelog.sgml,2.15,2.16

Fabian Keil <[email protected]>
Newsgroups gmane.comp.web.privoxy.cvs
Message-ID <[email protected]>
Update of /cvsroot/ijbswa/current/doc/source
In directory sfp-cvs-1.v30.ch3.sourceforge.com:/tmp/cvs-serv10105/doc/source

Modified Files:
	changelog.sgml 
Log Message:
Add CVEs for Privoxy 3.0.24


Index: changelog.sgml
===================================================================
RCS file: /cvsroot/ijbswa/current/doc/source/changelog.sgml,v
retrieving revision 2.15
retrieving revision 2.16
diff -C2 -d -r2.15 -r2.16
*** changelog.sgml	21 Jan 2016 15:57:16 -0000	2.15
--- changelog.sgml	22 Jan 2016 10:20:48 -0000	2.16
***************
*** 23,29 ****
  <para>
    <application>Privoxy 3.0.24</application> stable contains a couple
!   of new features but is mainly a bug-fix release. Two of the fixed bugs
!   are security issues (CVE requests pending) and may be used to remotely
!   trigger crashes on platforms that carefully check memory accesses (most don't).
  </para>
  
--- 23,29 ----
  <para>
    <application>Privoxy 3.0.24</application> stable contains a couple
!   of new features but is mainly a bug-fix release. Two of the fixed
!   bugs are security issues and may be used to remotely trigger crashes
!   on platforms that carefully check memory accesses (most don't).
  </para>
  
***************
*** 42,46 ****
       <para>
        Prevent invalid reads in case of corrupt chunk-encoded content.
!       Bug discovered with afl-fuzz and AddressSanitizer.
       </para>
      </listitem>
--- 42,46 ----
       <para>
        Prevent invalid reads in case of corrupt chunk-encoded content.
!       CVE-2016-1982. Bug discovered with afl-fuzz and AddressSanitizer.
       </para>
      </listitem>
***************
*** 48,52 ****
       <para>
        Remove empty Host headers in client requests.
!       Previously they would result in invalid reads.
        Bug discovered with afl-fuzz and AddressSanitizer.
       </para>
--- 48,52 ----
       <para>
        Remove empty Host headers in client requests.
!       Previously they would result in invalid reads. CVE-2016-1983.
        Bug discovered with afl-fuzz and AddressSanitizer.
       </para>


------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.