Loading STATUS +6 −3 Original line number Diff line number Diff line Loading @@ -150,9 +150,12 @@ PATCHES PROPOSED TO BACKPORT FROM TRUNK: should be much faster than a callout to strcmp. wrowe: Shouldn't this all simply be handled with an error result from apr_uri_parse? trawick: leaning towards (b) with wrowe's tweak above, to let other mods decide whether to handle odd URIs with core hook failing it if it got that far trawick: valid URIs can be used to exploit this, so apr_uri_parse() won't help Plan (b) from mail discussion above Adds trunk revision 1233604 2.2.x patch: http://people.apache.org/~trawick/CVE-2011-4317-2.2.x.txt +1: trawick * mod_proxy: cure size_t abuse part 1, backport relevant bits of r1227856, Specifically normalizes ap_proxy_string_read so that the prototype Loading Loading
STATUS +6 −3 Original line number Diff line number Diff line Loading @@ -150,9 +150,12 @@ PATCHES PROPOSED TO BACKPORT FROM TRUNK: should be much faster than a callout to strcmp. wrowe: Shouldn't this all simply be handled with an error result from apr_uri_parse? trawick: leaning towards (b) with wrowe's tweak above, to let other mods decide whether to handle odd URIs with core hook failing it if it got that far trawick: valid URIs can be used to exploit this, so apr_uri_parse() won't help Plan (b) from mail discussion above Adds trunk revision 1233604 2.2.x patch: http://people.apache.org/~trawick/CVE-2011-4317-2.2.x.txt +1: trawick * mod_proxy: cure size_t abuse part 1, backport relevant bits of r1227856, Specifically normalizes ap_proxy_string_read so that the prototype Loading