Loading STATUS +5 −0 Changes for STATUS: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -121,6 +121,11 @@ RELEASE SHOWSTOPPERS: memory usage. +1: trawick, wrowe * Commit http://people.apache.org/~wrowe/CVE-2010-0434.patch SECURITY: CVE-2010-0434 (cve.mitre.org) note; simpler because we had not yet cleaned up input headers for subreq +1: wrowe PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] Loading server/protocol.c +1 −1 Changes for server/protocol.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -1022,7 +1022,7 @@ AP_DECLARE(void) ap_set_sub_req_protocol(request_rec *rnew, rnew->status = HTTP_OK; rnew->headers_in = r->headers_in; rnew->headers_in = apr_table_copy(rnew->pool, r->headers_in); rnew->subprocess_env = apr_table_copy(rnew->pool, r->subprocess_env); rnew->headers_out = apr_table_make(rnew->pool, 5); rnew->err_headers_out = apr_table_make(rnew->pool, 5); Loading Loading
STATUS +5 −0 Changes for STATUS: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -121,6 +121,11 @@ RELEASE SHOWSTOPPERS: memory usage. +1: trawick, wrowe * Commit http://people.apache.org/~wrowe/CVE-2010-0434.patch SECURITY: CVE-2010-0434 (cve.mitre.org) note; simpler because we had not yet cleaned up input headers for subreq +1: wrowe PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] Loading
server/protocol.c +1 −1 Changes for server/protocol.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -1022,7 +1022,7 @@ AP_DECLARE(void) ap_set_sub_req_protocol(request_rec *rnew, rnew->status = HTTP_OK; rnew->headers_in = r->headers_in; rnew->headers_in = apr_table_copy(rnew->pool, r->headers_in); rnew->subprocess_env = apr_table_copy(rnew->pool, r->subprocess_env); rnew->headers_out = apr_table_make(rnew->pool, 5); rnew->err_headers_out = apr_table_make(rnew->pool, 5); Loading