Skip to content

Commit afdddab

Browse files
author
Claes Wikstrom
committed
prepare for 1.94
1 parent a8d2b52 commit afdddab

File tree

2 files changed

+6
-1
lines changed

2 files changed

+6
-1
lines changed

vsn.mk

+1-1
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
YAWS_VSN=1.93
1+
YAWS_VSN=1.94

www/news

+5
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1+
Sun Jun 24 23:47:57 CEST 2012
2+
Bugfix release for bugs that sneaked into 1.93
3+
The random patch for 1.93 wasn't good enough as discovered by Sergei Golovan, we need to cater for non printable chars (Sergei Golovan)
4+
add reverse proxy intercept module capability (Steve)
5+
16
Wed Jun 20 20:22:11 CEST 2012 Yaws 1.93
27
Security release
38
Use crypto:rand_bytes() instead of the cryptographically weak random module. Swedish security consultant and cryptographer Kalle Zetterlund discovered a way to - given a sequence of cookies produced by yaws_session_server - predict the next session id. Thus providing a gaping security hole into yaws servers that use the yaws_session_server to maintain cookie based HTTP sessions (klacke/kallez)

0 commit comments

Comments
 (0)