update for apache2
- specially crafted requests could bypass RewriteRule and ProxyPassMatch
- new template file: /etc/apache2/vhosts.d/vhost-ssl.template
allow TLSv1 only, browser match stuff commented out.
- rc script /etc/init.d/apache2: handle reload with deleted binaries
by message to stdout only, but refrain from sending signals.
-
Submitted by
Ludwig Nussel (lnussel)
Fixed bugs
bnc#722545
VUL-1: CVE-2011-3368: apache2: mod_proxy reverse proxy exposure