
Fix the description on CVE-2017-2640

2017-03-30, Richard Laager
Fix the description on CVE-2017-2640

It was an out-of-bounds write, not read.

This commit updates the ChangeLog file to match that in the
release-2.x.y branch (minus the bit for the unreleased version).
- Add Vary head to index.php and /download/index.php indicating that the content changes based on user-agent (because of OS autodetection).