Commit feb8f289 authored by Mark J. Cox's avatar Mark J. Cox
Browse files

http_protocol: Fix escaping of Expect error message

+1: mjc, trawick, rpluem, jim


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@395173 13f79535-47bb-0310-9956-ffa450edef68
parent 05bf887d
Loading
Loading
Loading
Loading
+5 −0
Changes for CHANGES: 5 added lines, 0 removed lines.
Original line number Diff line number Diff line
                                                        -*- coding: utf-8 -*-
Changes with Apache 2.2.2
  *) HTML-escape the Expect error message.  Not classed as security as
     an attacker has no way to influence the Expect header a victim will
     send to a target site.  Reported by Thiago Zaninotti
     <thiango nstalker.com>. [Mark Cox]
  *) htdbm: Warn the user when adding a plaintext password on a platform
     where it wouldn't work with the server (i.e., anywhere that has
     crypt()).  [Jeff Trawick]
+0 −7
Changes for STATUS: 0 added lines, 7 removed lines.
Original line number Diff line number Diff line
@@ -71,13 +71,6 @@ CURRENT RELEASE NOTES:

RELEASE SHOWSTOPPERS:

    * http_protocol: Fix escaping of Expect error message
        Trunk version of patch:
          http://svn.apache.org/viewcvs?rev=394965&view=rev
        2.2.x version of patch:
          Trunk version with changed offsets
       +1: mjc, trawick, rpluem, jim


PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
  [ start all new proposals below, under PATCHES PROPOSED. ]
+1 −1
Changes for modules/http/http_protocol.c: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -996,7 +996,7 @@ static const char *get_canned_error_string(int status,
                           "request-header"
                           "\nfield could not be met by this server.</p>\n"
                           "<p>The client sent<pre>\n    Expect: ",
                           apr_table_get(r->headers_in, "Expect"),
                           ap_escape_html(r->pool, apr_table_get(r->headers_in, "Expect")),
                           "\n</pre>\n"
                           "but we only allow the 100-continue "
                           "expectation.</p>\n",