Author: amc
Date: Mon Nov 3 18:10:37 2014
New Revision: 1636412
URL: http://svn.apache.org/r1636412
Log:
Better update for 5.1.1.
Submitted by: Alan M. Carroll
Reviewed by: Leif Hedstrom
Security: CVE-2014-3624
Modified:
trafficserver/site/trunk/content/downloads.en.mdtext
trafficserver/site/trunk/content/index.html
Modified: trafficserver/site/trunk/content/downloads.en.mdtext
URL:
http://svn.apache.org/viewvc/trafficserver/site/trunk/content/downloads.en.mdtext?rev=1636412&r1=1636411&r2=1636412&view=diff
==============================================================================
--- trafficserver/site/trunk/content/downloads.en.mdtext (original)
+++ trafficserver/site/trunk/content/downloads.en.mdtext Mon Nov 3 18:10:37
2014
@@ -41,7 +41,7 @@ and checksum signatures.
v5.1.1 is an incremental release over 5.0.1.
-More details are also in the [CHANGES
log](https://git-wip-us.apache.org/repos/asf?p=trafficserver.git;a=blob_plain;f=CHANGES;hb=refs/tags/5.1.1)
and the the Jira [Release
Notes](https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12324894&styleName=Html&projectId=12310963&Create=Create&atl_token=A5KQ-2QAV-T4JA-FDED%7Cceb8ed92ec8bf770f126e65e5fce4ce9335391fd%7Clout)
+More details are also in the [CHANGES
log](https://git-wip-us.apache.org/repos/asf?p=trafficserver.git;a=blob_plain;f=CHANGES;hb=refs/tags/5.1.1)
and the the Jira [Release
Notes](https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12327088&styleName=Html&projectId=12310963&Create=Create&atl_token=A5KQ-2QAV-T4JA-FDED%7Cfb6e85a9e82c27f61df95aadd1538645809197e9%7Clin)
# Current v4.x Release (Long Term Support) -- 4.2.2 # {#4.2.2}
Modified: trafficserver/site/trunk/content/index.html
URL:
http://svn.apache.org/viewvc/trafficserver/site/trunk/content/index.html?rev=1636412&r1=1636411&r2=1636412&view=diff
==============================================================================
--- trafficserver/site/trunk/content/index.html (original)
+++ trafficserver/site/trunk/content/index.html Mon Nov 3 18:10:37 2014
@@ -63,11 +63,17 @@
"http://ostatic.com/blog/guest-post-yahoos-cloud-team-open-sources-traffic-server">Traffic
Server overview</a>.</p>
<br>
- <P><b>Important security announcement</b>: All versions of Traffic
- Server prior to v5.0.1 (or v4.2.1.1) have a vulnerability related to
- the synthetic health checks as used by traffic_cop. We urge everyone
- to upgrade to the latest releases, either v4.2.1.1 or v5.1.1. See
- CVE-2014-3525 for some details.
+ <P><b>Important security announcements</b>:</P>
+ <P>
+ All versions of Traffic Server prior to v5.0.1 (or v4.2.1.1) have a
vulnerability related to
+ the synthetic health checks as used by traffic_cop. We urge everyone
+ to upgrade to the latest releases, either v4.2.1.1 or v5.1.1. See
+ CVE-2014-3525 for some details.
+ </P>
+ <p>
+ Traffic Server 5.1.0 has a security issue that can lead to acting as
an open relay under specific circumstances.
+ We urge all deployments of 5.1.0 to upgrade to 5.1.1. See
CVE-2014-3624 and TS-2677 for more detail.
+ </p>
</div>
</div>
<div class="fourcol right last">