Loading STATUS +9 −10 Original line number Diff line number Diff line Loading @@ -93,6 +93,15 @@ RELEASE SHOWSTOPPERS: PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] * mod_negotiation: Escape filenames in variant list to prevent an possible XSS for a site where untrusted users can upload files to a location with MultiViews enabled. SECURITY: CVE-2012-2687 (cve.mitre.org): Submitted by: Niels Heinen <heinenn google.com> trunk patch: http://svn.apache.org/viewvc?view=revision&revision=1349905 2.4.x patch: http://svn.apache.org/viewvc?view=revision&revision=1356889 2.2.x patch: trunk patch applies +1: rjung, trawick, wrowe PATCHES PROPOSED TO BACKPORT FROM TRUNK: [ New proposals should be added at the end of the list ] Loading Loading @@ -251,16 +260,6 @@ PATCHES PROPOSED TO BACKPORT FROM TRUNK: 2.2.x patch: http://people.apache.org/~rjung/patches/htdbm-htpasswd-handling_crypt_failure-2_2.patch +1: rjung * mod_negotiation: Escape filenames in variant list to prevent an possible XSS for a site where untrusted users can upload files to a location with MultiViews enabled. SECURITY: CVE-2012-2687 (cve.mitre.org): Submitted by: Niels Heinen <heinenn google.com> trunk patch: http://svn.apache.org/viewvc?view=revision&revision=1349905 2.4.x patch: http://svn.apache.org/viewvc?view=revision&revision=1356889 2.2.x patch: trunk patch applies +1: rjung, trawick * mod_rewrite: add "AllowAnyURI" option. Prerequisites: - allow the user to configure which rules come first when RewriteRules Loading Loading
STATUS +9 −10 Original line number Diff line number Diff line Loading @@ -93,6 +93,15 @@ RELEASE SHOWSTOPPERS: PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] * mod_negotiation: Escape filenames in variant list to prevent an possible XSS for a site where untrusted users can upload files to a location with MultiViews enabled. SECURITY: CVE-2012-2687 (cve.mitre.org): Submitted by: Niels Heinen <heinenn google.com> trunk patch: http://svn.apache.org/viewvc?view=revision&revision=1349905 2.4.x patch: http://svn.apache.org/viewvc?view=revision&revision=1356889 2.2.x patch: trunk patch applies +1: rjung, trawick, wrowe PATCHES PROPOSED TO BACKPORT FROM TRUNK: [ New proposals should be added at the end of the list ] Loading Loading @@ -251,16 +260,6 @@ PATCHES PROPOSED TO BACKPORT FROM TRUNK: 2.2.x patch: http://people.apache.org/~rjung/patches/htdbm-htpasswd-handling_crypt_failure-2_2.patch +1: rjung * mod_negotiation: Escape filenames in variant list to prevent an possible XSS for a site where untrusted users can upload files to a location with MultiViews enabled. SECURITY: CVE-2012-2687 (cve.mitre.org): Submitted by: Niels Heinen <heinenn google.com> trunk patch: http://svn.apache.org/viewvc?view=revision&revision=1349905 2.4.x patch: http://svn.apache.org/viewvc?view=revision&revision=1356889 2.2.x patch: trunk patch applies +1: rjung, trawick * mod_rewrite: add "AllowAnyURI" option. Prerequisites: - allow the user to configure which rules come first when RewriteRules Loading