Loading CHANGES +5 −0 Changes for CHANGES: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -17,6 +17,11 @@ Changes with Apache 2.0.62 shutdown of the server when the MaxClients is higher then 257, in a more responsive manner [Mladen Turk, William Rowe] *) Add explicit charset to the output of various modules to work around possible cross-site scripting flaws affecting web browsers that do not derive the response character set as required by RFC2616. One of these reported by SecurityReason [Joe Orton] *) http_protocol: Escape request method in 405 error reporting. This has no security impact since the browser cannot be tricked into sending arbitrary method strings. [Jeff Trawick] Loading STATUS +0 −10 Changes for STATUS: 0 added lines, 10 removed lines. Original line number Diff line number Diff line Loading @@ -113,16 +113,6 @@ CURRENT RELEASE NOTES: RELEASE SHOWSTOPPERS: * Various modules: Add explicit charset to the output of various modules to work around possible cross-site scripting flaws affecting web browsers that do not derive the response character set as required by RFC2616. Trunk version of patch: http://svn.apache.org/viewvc?rev=606693&view=rev http://svn.apache.org/viewvc?rev=607276&view=rev Backport version for 2.0.x of patch: http://people.apache.org/~rpluem/patches/utf7_fix_2.0.x.diff +1: rpluem, wrowe, jim PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] Loading modules/dav/main/mod_dav.c +1 −1 Changes for modules/dav/main/mod_dav.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -317,7 +317,7 @@ static int dav_error_response(request_rec *r, int status, const char *body) /* ### I really don't think this is needed; gotta test */ r->status_line = ap_get_status_line(status); ap_set_content_type(r, "text/html"); ap_set_content_type(r, "text/html; charset=ISO-8859-1"); /* begin the response now... */ ap_rvputs(r, Loading modules/experimental/util_ldap.c +1 −1 Changes for modules/experimental/util_ldap.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -139,7 +139,7 @@ int util_ldap_handler(request_rec *r) return DECLINED; } r->content_type = "text/html"; r->content_type = "text/html; charset=ISO-8859-1"; if (r->header_only) return OK; Loading modules/generators/mod_info.c +1 −1 Changes for modules/generators/mod_info.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -318,7 +318,7 @@ static int display_info(request_rec *r) if (r->method_number != M_GET) return DECLINED; ap_set_content_type(r, "text/html"); ap_set_content_type(r, "text/html; charset=ISO-8859-1"); ap_rputs(DOCTYPE_HTML_3_2 "<html><head><title>Server Information</title></head>\n", r); Loading Loading
CHANGES +5 −0 Changes for CHANGES: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -17,6 +17,11 @@ Changes with Apache 2.0.62 shutdown of the server when the MaxClients is higher then 257, in a more responsive manner [Mladen Turk, William Rowe] *) Add explicit charset to the output of various modules to work around possible cross-site scripting flaws affecting web browsers that do not derive the response character set as required by RFC2616. One of these reported by SecurityReason [Joe Orton] *) http_protocol: Escape request method in 405 error reporting. This has no security impact since the browser cannot be tricked into sending arbitrary method strings. [Jeff Trawick] Loading
STATUS +0 −10 Changes for STATUS: 0 added lines, 10 removed lines. Original line number Diff line number Diff line Loading @@ -113,16 +113,6 @@ CURRENT RELEASE NOTES: RELEASE SHOWSTOPPERS: * Various modules: Add explicit charset to the output of various modules to work around possible cross-site scripting flaws affecting web browsers that do not derive the response character set as required by RFC2616. Trunk version of patch: http://svn.apache.org/viewvc?rev=606693&view=rev http://svn.apache.org/viewvc?rev=607276&view=rev Backport version for 2.0.x of patch: http://people.apache.org/~rpluem/patches/utf7_fix_2.0.x.diff +1: rpluem, wrowe, jim PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] Loading
modules/dav/main/mod_dav.c +1 −1 Changes for modules/dav/main/mod_dav.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -317,7 +317,7 @@ static int dav_error_response(request_rec *r, int status, const char *body) /* ### I really don't think this is needed; gotta test */ r->status_line = ap_get_status_line(status); ap_set_content_type(r, "text/html"); ap_set_content_type(r, "text/html; charset=ISO-8859-1"); /* begin the response now... */ ap_rvputs(r, Loading
modules/experimental/util_ldap.c +1 −1 Changes for modules/experimental/util_ldap.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -139,7 +139,7 @@ int util_ldap_handler(request_rec *r) return DECLINED; } r->content_type = "text/html"; r->content_type = "text/html; charset=ISO-8859-1"; if (r->header_only) return OK; Loading
modules/generators/mod_info.c +1 −1 Changes for modules/generators/mod_info.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -318,7 +318,7 @@ static int display_info(request_rec *r) if (r->method_number != M_GET) return DECLINED; ap_set_content_type(r, "text/html"); ap_set_content_type(r, "text/html; charset=ISO-8859-1"); ap_rputs(DOCTYPE_HTML_3_2 "<html><head><title>Server Information</title></head>\n", r); Loading