Commit 2fb8ee8f authored by Nick Kew's avatar Nick Kew
Browse files

Fix PR#38070

Avoid server-driven negotiation when a script has sent a Status: header.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@374894 13f79535-47bb-0310-9956-ffa450edef68
parent a6f2c915
Loading
Loading
Loading
Loading
+3 −0
Changes for CHANGES: 3 added lines, 0 removed lines.
Original line number Diff line number Diff line
                                                         -*- coding: utf-8 -*-
Changes with Apache 2.0.56
  *) Fix PR#38070: Avoid server-driven negotiation when a CGI script
     has emitted an explicit Status: header [Nick Kew].
  *) SECURITY: CVE-2005-3357 (cve.mitre.org)
     mod_ssl: Fix a possible crash during access control checks if a
     non-SSL request is processed for an SSL vhost (such as the
+0 −5
Changes for STATUS: 0 added lines, 5 removed lines.
Original line number Diff line number Diff line
@@ -117,11 +117,6 @@ PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
         http://svn.apache.org/viewcvs?view=rev&rev=154319
       +1: stoddard, striker, wrowe (as corrected in subsequent patches)

    *) util_script: FIX PR38070, correctly honor a CGI Status: header.
         http://svn.apache.org/viewcvs?rev=370692&view=rev
       +1: colm,niq,wrowe


PATCHES PROPOSED TO BACKPORT FROM TRUNK:
  [ please place SVN revisions from trunk here, so it is easy to
    identify exactly what the proposed changes are!  Add all new
+15 −2
Changes for server/util_script.c: 15 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -394,6 +394,8 @@ static int set_cookie_doo_doo(void *v, const char *key, const char *val)
    return 1;
}

#define HTTP_UNSET (-HTTP_OK)

AP_DECLARE(int) ap_scan_script_header_err_core(request_rec *r, char *buffer,
				       int (*getsfunc) (char *, int, void *),
				       void *getsfunc_data)
@@ -401,7 +403,7 @@ AP_DECLARE(int) ap_scan_script_header_err_core(request_rec *r, char *buffer,
    char x[MAX_STRING_LEN];
    char *w, *l;
    int p;
    int cgi_status = HTTP_OK;
    int cgi_status = HTTP_UNSET;
    apr_table_t *merge;
    apr_table_t *cookie_table;

@@ -462,7 +464,18 @@ AP_DECLARE(int) ap_scan_script_header_err_core(request_rec *r, char *buffer,
	if (w[0] == '\0') {
	    int cond_status = OK;

	    if ((cgi_status == HTTP_OK) && (r->method_number == M_GET)) {
	    /* PR#38070: This fails because it gets confused when a
             * CGI Status header overrides ap_meets_conditions.
             * 
             * We can fix that by dropping ap_meets_conditions when
             * Status has been set.  Since this is the only place
             * cgi_status gets used, let's test it explicitly.
             *
             * The alternative would be to ignore CGI Status when
             * ap_meets_conditions returns anything interesting.
             * That would be safer wrt HTTP, but would break CGI.
             */
	    if ((cgi_status == HTTP_UNSET) && (r->method_number == M_GET)) {
		cond_status = ap_meets_conditions(r);
	    }
	    apr_table_overlap(r->err_headers_out, merge,