Loading CHANGES +5 −0 Changes for CHANGES: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Changes with Apache 2.0.50 *) SECURITY: CAN-2004-0493 (cve.mitre.org) Close a denial of service vulnerability identified by Georgi Guninski which could lead to memory exhaustion with certain input data. [Jeff Trawick] *) mod_cgi: Handle output on stderr during script execution on Unix platforms; preventing deadlock when stderr output fills pipe buffer. Also fixes case where stderr from nph- scripts could be lost. Loading server/protocol.c +17 −0 Changes for server/protocol.c: 17 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -719,6 +719,23 @@ AP_DECLARE(void) ap_get_mime_headers_core(request_rec *r, apr_bucket_brigade *bb * continuations that span many many lines. */ apr_size_t fold_len = last_len + len + 1; /* trailing null */ if ((fold_len - 1) > r->server->limit_req_fieldsize) { r->status = HTTP_BAD_REQUEST; /* report what we have accumulated so far before the * overflow (last_field) as the field with the problem */ apr_table_setn(r->notes, "error-notes", apr_pstrcat(r->pool, "Size of a request header field " "after folding " "exceeds server limit.<br />\n" "<pre>\n", ap_escape_html(r->pool, last_field), "</pre>\n", NULL)); return; } if (fold_len > alloc_len) { char *fold_buf; alloc_len += alloc_len; Loading Loading
CHANGES +5 −0 Changes for CHANGES: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Changes with Apache 2.0.50 *) SECURITY: CAN-2004-0493 (cve.mitre.org) Close a denial of service vulnerability identified by Georgi Guninski which could lead to memory exhaustion with certain input data. [Jeff Trawick] *) mod_cgi: Handle output on stderr during script execution on Unix platforms; preventing deadlock when stderr output fills pipe buffer. Also fixes case where stderr from nph- scripts could be lost. Loading
server/protocol.c +17 −0 Changes for server/protocol.c: 17 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -719,6 +719,23 @@ AP_DECLARE(void) ap_get_mime_headers_core(request_rec *r, apr_bucket_brigade *bb * continuations that span many many lines. */ apr_size_t fold_len = last_len + len + 1; /* trailing null */ if ((fold_len - 1) > r->server->limit_req_fieldsize) { r->status = HTTP_BAD_REQUEST; /* report what we have accumulated so far before the * overflow (last_field) as the field with the problem */ apr_table_setn(r->notes, "error-notes", apr_pstrcat(r->pool, "Size of a request header field " "after folding " "exceeds server limit.<br />\n" "<pre>\n", ap_escape_html(r->pool, last_field), "</pre>\n", NULL)); return; } if (fold_len > alloc_len) { char *fold_buf; alloc_len += alloc_len; Loading