Skip to content
  1. Dec 30, 2009
  2. Dec 29, 2009
  3. Dec 27, 2009
  4. Dec 26, 2009
  5. Dec 25, 2009
  6. Dec 23, 2009
  7. Dec 22, 2009
  8. Dec 21, 2009
  9. Dec 20, 2009
  10. Dec 18, 2009
  11. Dec 16, 2009
    • Joe Orton's avatar
      Further mitigation for the TLS renegotation attack, CVE-2009-3555: · 0a4c1543
      Joe Orton authored
      * modules/ssl/ssl_engine_kernel.c (has_buffered_data): New function.
        (ssl_hook_Access): Forcibly disable keepalive for the connection if
        there is any buffered data readable from the input filter stack.
      
      * modules/ssl/ssl_engine_io.c (ssl_io_filter_input): Ensure that the
        BIO uses blocking operations when invoked outside direct control of
        the httpd filter stack.
      
      Thanks to Hartmut Keil <Hartmut.Keil adnovum.ch> for proposing this
      technique.
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@891282 13f79535-47bb-0310-9956-ffa450edef68
      0a4c1543