Loading CHANGES +5 −0 Changes for CHANGES: 5 added lines, 0 removed lines. Original line number Diff line number Diff line -*- coding: utf-8 -*- Changes with Apache 2.2.2 *) HTML-escape the Expect error message. Not classed as security as an attacker has no way to influence the Expect header a victim will send to a target site. Reported by Thiago Zaninotti <thiango nstalker.com>. [Mark Cox] *) htdbm: Warn the user when adding a plaintext password on a platform where it wouldn't work with the server (i.e., anywhere that has crypt()). [Jeff Trawick] Loading STATUS +0 −7 Changes for STATUS: 0 added lines, 7 removed lines. Original line number Diff line number Diff line Loading @@ -71,13 +71,6 @@ CURRENT RELEASE NOTES: RELEASE SHOWSTOPPERS: * http_protocol: Fix escaping of Expect error message Trunk version of patch: http://svn.apache.org/viewcvs?rev=394965&view=rev 2.2.x version of patch: Trunk version with changed offsets +1: mjc, trawick, rpluem, jim PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] Loading modules/http/http_protocol.c +1 −1 Changes for modules/http/http_protocol.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -996,7 +996,7 @@ static const char *get_canned_error_string(int status, "request-header" "\nfield could not be met by this server.</p>\n" "<p>The client sent<pre>\n Expect: ", apr_table_get(r->headers_in, "Expect"), ap_escape_html(r->pool, apr_table_get(r->headers_in, "Expect")), "\n</pre>\n" "but we only allow the 100-continue " "expectation.</p>\n", Loading Loading
CHANGES +5 −0 Changes for CHANGES: 5 added lines, 0 removed lines. Original line number Diff line number Diff line -*- coding: utf-8 -*- Changes with Apache 2.2.2 *) HTML-escape the Expect error message. Not classed as security as an attacker has no way to influence the Expect header a victim will send to a target site. Reported by Thiago Zaninotti <thiango nstalker.com>. [Mark Cox] *) htdbm: Warn the user when adding a plaintext password on a platform where it wouldn't work with the server (i.e., anywhere that has crypt()). [Jeff Trawick] Loading
STATUS +0 −7 Changes for STATUS: 0 added lines, 7 removed lines. Original line number Diff line number Diff line Loading @@ -71,13 +71,6 @@ CURRENT RELEASE NOTES: RELEASE SHOWSTOPPERS: * http_protocol: Fix escaping of Expect error message Trunk version of patch: http://svn.apache.org/viewcvs?rev=394965&view=rev 2.2.x version of patch: Trunk version with changed offsets +1: mjc, trawick, rpluem, jim PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] Loading
modules/http/http_protocol.c +1 −1 Changes for modules/http/http_protocol.c: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -996,7 +996,7 @@ static const char *get_canned_error_string(int status, "request-header" "\nfield could not be met by this server.</p>\n" "<p>The client sent<pre>\n Expect: ", apr_table_get(r->headers_in, "Expect"), ap_escape_html(r->pool, apr_table_get(r->headers_in, "Expect")), "\n</pre>\n" "but we only allow the 100-continue " "expectation.</p>\n", Loading