Skip to content

Commit 5b83e7d

Browse files
committed
publishing release httpd-2.4.65
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1927439 13f79535-47bb-0310-9956-ffa450edef68
1 parent 8781a31 commit 5b83e7d

File tree

11 files changed

+40
-24
lines changed

11 files changed

+40
-24
lines changed

CHANGES

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,15 @@
11
-*- coding: utf-8 -*-
2+
Changes with Apache 2.4.66
3+
24
Changes with Apache 2.4.65
35

6+
*) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr'
7+
always evaluates to true in 2.4.64 (cve.mitre.org)
8+
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond
9+
expr ..." tests evaluating as "true".
10+
Users are recommended to upgrade to version 2.4.65, which fixes
11+
the issue.
12+
413
Changes with Apache 2.4.64
514

615
*) SECURITY: CVE-2025-53020: Apache HTTP Server: HTTP/2 DoS by

STATUS

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,8 @@ Release history:
2929
[NOTE that x.{odd}.z versions are strictly Alpha/Beta releases,
3030
while x.{even}.z versions are Stable/GA releases.]
3131

32-
2.4.65 : In development
32+
2.4.66 : In development
33+
2.4.65 : Released on July 23, 2025
3334
2.4.64 : Released on July 10, 2025
3435
2.4.63 : Released on January 23, 2025
3536
2.4.62 : Released on July 17, 2024

docs/manual/convenience.map

Lines changed: 21 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,7 @@ addoutputfilterbytype mod/mod_filter.html#addoutputfilterbytype
2929
addtype mod/mod_mime.html#addtype
3030
alias mod/mod_alias.html#alias
3131
aliasmatch mod/mod_alias.html#aliasmatch
32+
aliaspreservepath mod/mod_alias.html#aliaspreservepath
3233
allow mod/mod_access_compat.html#allow
3334
allowconnect mod/mod_proxy_connect.html#allowconnect
3435
allowencodedslashes mod/core.html#allowencodedslashes
@@ -162,6 +163,7 @@ cachestoreprivate mod/mod_cache.html#cachestoreprivate
162163
cgidscripttimeout mod/mod_cgid.html#cgidscripttimeout
163164
cgimapextension mod/core.html#cgimapextension
164165
cgipassauth mod/core.html#cgipassauth
166+
cgiscripttimeout mod/mod_cgi.html#cgiscripttimeout
165167
cgivar mod/core.html#cgivar
166168
charsetdefault mod/mod_charset_lite.html#charsetdefault
167169
charsetoptions mod/mod_charset_lite.html#charsetoptions
@@ -182,9 +184,11 @@ cookietracking mod/mod_usertrack.html#cookietracking
182184
coredumpdirectory mod/mpm_common.html#coredumpdirectory
183185
customlog mod/mod_log_config.html#customlog
184186
dav mod/mod_dav.html#dav
187+
davbasepath mod/mod_dav.html#davbasepath
185188
davdepthinfinity mod/mod_dav.html#davdepthinfinity
186189
davgenericlockdb mod/mod_dav_lock.html#davgenericlockdb
187190
davlockdb mod/mod_dav_fs.html#davlockdb
191+
davlockdiscovery mod/mod_dav_fs.html#davlockdiscovery
188192
davmintimeout mod/mod_dav.html#davmintimeout
189193
dbdexptime mod/mod_dbd.html#dbdexptime
190194
dbdinitsql mod/mod_dbd.html#dbdinitsql
@@ -200,6 +204,7 @@ defaultlanguage mod/mod_mime.html#defaultlanguage
200204
defaultruntimedir mod/core.html#defaultruntimedir
201205
defaulttype mod/core.html#defaulttype
202206
define mod/core.html#define
207+
deflatealteretag mod/mod_deflate.html#deflatealteretag
203208
deflatebuffersize mod/mod_deflate.html#deflatebuffersize
204209
deflatecompressionlevel mod/mod_deflate.html#deflatecompressionlevel
205210
deflatefilternote mod/mod_deflate.html#deflatefilternote
@@ -255,23 +260,29 @@ gracefulshutdowntimeout mod/mpm_common.html#gracefulshutdowntimeout
255260
group mod/mod_unixd.html#group
256261
h2copyfiles mod/mod_http2.html#h2copyfiles
257262
h2direct mod/mod_http2.html#h2direct
263+
h2earlyhint mod/mod_http2.html#h2earlyhint
258264
h2earlyhints mod/mod_http2.html#h2earlyhints
265+
h2maxdataframelen mod/mod_http2.html#h2maxdataframelen
266+
h2maxheaderblocklen mod/mod_http2.html#h2maxheaderblocklen
259267
h2maxsessionstreams mod/mod_http2.html#h2maxsessionstreams
260268
h2maxworkeridleseconds mod/mod_http2.html#h2maxworkeridleseconds
261269
h2maxworkers mod/mod_http2.html#h2maxworkers
262270
h2minworkers mod/mod_http2.html#h2minworkers
263271
h2moderntlsonly mod/mod_http2.html#h2moderntlsonly
264272
h2outputbuffering mod/mod_http2.html#h2outputbuffering
265273
h2padding mod/mod_http2.html#h2padding
274+
h2proxyrequests mod/mod_http2.html#h2proxyrequests
266275
h2push mod/mod_http2.html#h2push
267276
h2pushdiarysize mod/mod_http2.html#h2pushdiarysize
268277
h2pushpriority mod/mod_http2.html#h2pushpriority
269278
h2pushresource mod/mod_http2.html#h2pushresource
270279
h2serializeheaders mod/mod_http2.html#h2serializeheaders
271280
h2streammaxmemsize mod/mod_http2.html#h2streammaxmemsize
281+
h2streamtimeout mod/mod_http2.html#h2streamtimeout
272282
h2tlscooldownsecs mod/mod_http2.html#h2tlscooldownsecs
273283
h2tlswarmupsize mod/mod_http2.html#h2tlswarmupsize
274284
h2upgrade mod/mod_http2.html#h2upgrade
285+
h2websockets mod/mod_http2.html#h2websockets
275286
h2windowsize mod/mod_http2.html#h2windowsize
276287
header mod/mod_headers.html#header
277288
headername mod/mod_autoindex.html#headername
@@ -394,10 +405,13 @@ mdcertificatemonitor mod/mod_md.html#mdcertificatemonitor
394405
mdcertificateprotocol mod/mod_md.html#mdcertificateprotocol
395406
mdcertificatestatus mod/mod_md.html#mdcertificatestatus
396407
mdchallengedns01 mod/mod_md.html#mdchallengedns01
408+
mdchallengedns01version mod/mod_md.html#mdchallengedns01version
409+
mdcheckinterval mod/mod_md.html#mdcheckinterval
397410
mdcontactemail mod/mod_md.html#mdcontactemail
398411
mddrivemode mod/mod_md.html#mddrivemode
399412
mdexternalaccountbinding mod/mod_md.html#mdexternalaccountbinding
400413
mdhttpproxy mod/mod_md.html#mdhttpproxy
414+
mdmatchnames mod/mod_md.html#mdmatchnames
401415
mdmember mod/mod_md.html#mdmember
402416
mdmembers mod/mod_md.html#mdmembers
403417
mdmessagecmd mod/mod_md.html#mdmessagecmd
@@ -407,15 +421,20 @@ mdomain mod/mod_md.html#mdomain
407421
mdomainset mod/mod_md.html#mdomainset
408422
mdportmap mod/mod_md.html#mdportmap
409423
mdprivatekeys mod/mod_md.html#mdprivatekeys
424+
mdprofile mod/mod_md.html#mdprofile
425+
mdprofilemandatory mod/mod_md.html#mdprofilemandatory
410426
mdrenewmode mod/mod_md.html#mdrenewmode
411427
mdrenewwindow mod/mod_md.html#mdrenewwindow
412428
mdrequirehttps mod/mod_md.html#mdrequirehttps
429+
mdretrydelay mod/mod_md.html#mdretrydelay
430+
mdretryfailover mod/mod_md.html#mdretryfailover
413431
mdserverstatus mod/mod_md.html#mdserverstatus
414432
mdstapleothers mod/mod_md.html#mdstapleothers
415433
mdstapling mod/mod_md.html#mdstapling
416434
mdstaplingkeepresponse mod/mod_md.html#mdstaplingkeepresponse
417435
mdstaplingrenewwindow mod/mod_md.html#mdstaplingrenewwindow
418436
mdstoredir mod/mod_md.html#mdstoredir
437+
mdstorelocks mod/mod_md.html#mdstorelocks
419438
mdwarnwindow mod/mod_md.html#mdwarnwindow
420439
memcacheconnttl mod/mod_socache_memcache.html#memcacheconnttl
421440
mergeslashes mod/core.html#mergeslashes
@@ -505,6 +524,7 @@ receivebuffersize mod/mpm_common.html#receivebuffersize
505524
redirect mod/mod_alias.html#redirect
506525
redirectmatch mod/mod_alias.html#redirectmatch
507526
redirectpermanent mod/mod_alias.html#redirectpermanent
527+
redirectrelative mod/mod_alias.html#redirectrelative
508528
redirecttemp mod/mod_alias.html#redirecttemp
509529
redisconnpoolttl mod/mod_socache_redis.html#redisconnpoolttl
510530
redistimeout mod/mod_socache_redis.html#redistimeout
@@ -682,24 +702,10 @@ threadlimit mod/mpm_common.html#threadlimit
682702
threadsperchild mod/mpm_common.html#threadsperchild
683703
threadstacksize mod/mpm_common.html#threadstacksize
684704
timeout mod/core.html#timeout
685-
tlscertificate mod/mod_tls.html#tlscertificate
686-
tlsciphersprefer mod/mod_tls.html#tlsciphersprefer
687-
tlscipherssuppress mod/mod_tls.html#tlscipherssuppress
688-
tlsengine mod/mod_tls.html#tlsengine
689-
tlshonorclientorder mod/mod_tls.html#tlshonorclientorder
690-
tlsoptions mod/mod_tls.html#tlsoptions
691-
tlsprotocol mod/mod_tls.html#tlsprotocol
692-
tlsproxyca mod/mod_tls.html#tlsproxyca
693-
tlsproxyciphersprefer mod/mod_tls.html#tlsproxyciphersprefer
694-
tlsproxycipherssuppress mod/mod_tls.html#tlsproxycipherssuppress
695-
tlsproxyengine mod/mod_tls.html#tlsproxyengine
696-
tlsproxymachinecertificate mod/mod_tls.html#tlsproxymachinecertificate
697-
tlsproxyprotocol mod/mod_tls.html#tlsproxyprotocol
698-
tlssessioncache mod/mod_tls.html#tlssessioncache
699-
tlsstrictsni mod/mod_tls.html#tlsstrictsni
700705
traceenable mod/core.html#traceenable
701706
transferlog mod/mod_log_config.html#transferlog
702707
typesconfig mod/mod_mime.html#typesconfig
708+
unclist mod/core.html#unclist
703709
undefine mod/core.html#undefine
704710
undefmacro mod/mod_macro.html#undefmacro
705711
unsetenv mod/mod_env.html#unsetenv

docs/manual/mod/quickreference.html.de

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1087,7 +1087,7 @@ Client Auth</td></tr>
10871087
handshake</td></tr>
10881088
<tr><td><a href="mod_ssl.html#sslcompression">SSLCompression on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Enable compression on the SSL level</td></tr>
10891089
<tr class="odd"><td><a href="mod_ssl.html#sslcryptodevice">SSLCryptoDevice <em>engine</em></a></td><td> builtin </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Enable use of a cryptographic hardware accelerator</td></tr>
1090-
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off|optional</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
1090+
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
10911091
<tr class="odd"><td><a href="mod_ssl.html#sslfips">SSLFIPS on|off</a></td><td> off </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">SSL FIPS mode Switch</td></tr>
10921092
<tr><td><a href="mod_ssl.html#sslhonorcipherorder">SSLHonorCipherOrder on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Option to prefer the server's cipher preference order</td></tr>
10931093
<tr class="odd"><td><a href="mod_ssl.html#sslinsecurerenegotiation">SSLInsecureRenegotiation on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Option to enable support for insecure renegotiation</td></tr>

docs/manual/mod/quickreference.html.es

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1078,7 +1078,7 @@ Client Auth</td></tr>
10781078
handshake</td></tr>
10791079
<tr><td><a href="mod_ssl.html#sslcompression">SSLCompression on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Enable compression on the SSL level</td></tr>
10801080
<tr class="odd"><td><a href="mod_ssl.html#sslcryptodevice">SSLCryptoDevice <em>engine</em></a></td><td> builtin </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Enable use of a cryptographic hardware accelerator</td></tr>
1081-
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off|optional</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
1081+
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
10821082
<tr class="odd"><td><a href="mod_ssl.html#sslfips">SSLFIPS on|off</a></td><td> off </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">SSL FIPS mode Switch</td></tr>
10831083
<tr><td><a href="mod_ssl.html#sslhonorcipherorder">SSLHonorCipherOrder on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Option to prefer the server's cipher preference order</td></tr>
10841084
<tr class="odd"><td><a href="mod_ssl.html#sslinsecurerenegotiation">SSLInsecureRenegotiation on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Option to enable support for insecure renegotiation</td></tr>

docs/manual/mod/quickreference.html.ja.utf8

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1005,7 +1005,7 @@ Client Auth</td></tr>
10051005
handshake</td></tr>
10061006
<tr><td><a href="mod_ssl.html#sslcompression">SSLCompression on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Enable compression on the SSL level</td></tr>
10071007
<tr class="odd"><td><a href="mod_ssl.html#sslcryptodevice">SSLCryptoDevice <em>engine</em></a></td><td> builtin </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Enable use of a cryptographic hardware accelerator</td></tr>
1008-
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off|optional</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
1008+
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
10091009
<tr class="odd"><td><a href="mod_ssl.html#sslfips">SSLFIPS on|off</a></td><td> off </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">SSL FIPS mode Switch</td></tr>
10101010
<tr><td><a href="mod_ssl.html#sslhonorcipherorder">SSLHonorCipherOrder on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Option to prefer the server's cipher preference order</td></tr>
10111011
<tr class="odd"><td><a href="mod_ssl.html#sslinsecurerenegotiation">SSLInsecureRenegotiation on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Option to enable support for insecure renegotiation</td></tr>

docs/manual/mod/quickreference.html.ko.euc-kr

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1034,7 +1034,7 @@ Client Auth</td></tr>
10341034
handshake</td></tr>
10351035
<tr><td><a href="mod_ssl.html#sslcompression">SSLCompression on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Enable compression on the SSL level</td></tr>
10361036
<tr class="odd"><td><a href="mod_ssl.html#sslcryptodevice">SSLCryptoDevice <em>engine</em></a></td><td> builtin </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Enable use of a cryptographic hardware accelerator</td></tr>
1037-
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off|optional</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
1037+
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
10381038
<tr class="odd"><td><a href="mod_ssl.html#sslfips">SSLFIPS on|off</a></td><td> off </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">SSL FIPS mode Switch</td></tr>
10391039
<tr><td><a href="mod_ssl.html#sslhonorcipherorder">SSLHonorCipherOrder on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Option to prefer the server's cipher preference order</td></tr>
10401040
<tr class="odd"><td><a href="mod_ssl.html#sslinsecurerenegotiation">SSLInsecureRenegotiation on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Option to enable support for insecure renegotiation</td></tr>

docs/manual/mod/quickreference.html.tr.utf8

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1068,7 +1068,7 @@ Client Auth</td></tr>
10681068
handshake</td></tr>
10691069
<tr><td><a href="mod_ssl.html#sslcompression">SSLCompression on|off</a></td><td> off </td><td>sk</td><td>E</td></tr><tr><td class="descr" colspan="4">Enable compression on the SSL level</td></tr>
10701070
<tr class="odd"><td><a href="mod_ssl.html#sslcryptodevice">SSLCryptoDevice <em>engine</em></a></td><td> builtin </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Enable use of a cryptographic hardware accelerator</td></tr>
1071-
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off|optional</a></td><td> off </td><td>sk</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
1071+
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off</a></td><td> off </td><td>sk</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
10721072
<tr class="odd"><td><a href="mod_ssl.html#sslfips">SSLFIPS on|off</a></td><td> off </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">SSL FIPS mode Switch</td></tr>
10731073
<tr><td><a href="mod_ssl.html#sslhonorcipherorder">SSLHonorCipherOrder on|off</a></td><td> off </td><td>sk</td><td>E</td></tr><tr><td class="descr" colspan="4">Option to prefer the server's cipher preference order</td></tr>
10741074
<tr class="odd"><td><a href="mod_ssl.html#sslinsecurerenegotiation">SSLInsecureRenegotiation on|off</a></td><td> off </td><td>sk</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Option to enable support for insecure renegotiation</td></tr>

docs/manual/mod/quickreference.html.zh-cn.utf8

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1070,7 +1070,7 @@ Client Auth</td></tr>
10701070
handshake</td></tr>
10711071
<tr><td><a href="mod_ssl.html#sslcompression">SSLCompression on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Enable compression on the SSL level</td></tr>
10721072
<tr class="odd"><td><a href="mod_ssl.html#sslcryptodevice">SSLCryptoDevice <em>engine</em></a></td><td> builtin </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Enable use of a cryptographic hardware accelerator</td></tr>
1073-
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off|optional</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
1073+
<tr><td><a href="mod_ssl.html#sslengine">SSLEngine on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">SSL Engine Operation Switch</td></tr>
10741074
<tr class="odd"><td><a href="mod_ssl.html#sslfips">SSLFIPS on|off</a></td><td> off </td><td>s</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">SSL FIPS mode Switch</td></tr>
10751075
<tr><td><a href="mod_ssl.html#sslhonorcipherorder">SSLHonorCipherOrder on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr><td class="descr" colspan="4">Option to prefer the server's cipher preference order</td></tr>
10761076
<tr class="odd"><td><a href="mod_ssl.html#sslinsecurerenegotiation">SSLInsecureRenegotiation on|off</a></td><td> off </td><td>sv</td><td>E</td></tr><tr class="odd"><td class="descr" colspan="4">Option to enable support for insecure renegotiation</td></tr>

docs/manual/style/version.ent

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,6 @@
1919

2020
<!ENTITY httpd.major "2">
2121
<!ENTITY httpd.minor "4">
22-
<!ENTITY httpd.patch "65">
22+
<!ENTITY httpd.patch "66">
2323

2424
<!ENTITY httpd.docs "2.4">

0 commit comments

Comments
 (0)