1. 28 Sep, 2010 1 commit
    • Rainer Jung's avatar
      Merge r891282 from trunk resp. 896900 from 2.2.x: · 3ecd6d7f
      Rainer Jung authored
      Further mitigation for the TLS renegotation attack, CVE-2009-3555:
      
      * modules/ssl/ssl_engine_kernel.c (has_buffered_data): New function.
        (ssl_hook_Access): Forcibly disable keepalive for the connection if
        there is any buffered data readable from the input filter stack.
      
      * modules/ssl/ssl_engine_io.c (ssl_io_filter_input): Ensure that the
        BIO uses blocking operations when invoked outside direct control of
        the httpd filter stack.
      
      Thanks to Hartmut Keil <Hartmut.Keil adnovum.ch> for proposing this
      technique.
      
      Submitted by: jorton
      Backport by: rjung
      Reviewed by: pgollucci, wrowe
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@1002227 13f79535-47bb-0310-9956-ffa450edef68
      3ecd6d7f
  2. 27 Sep, 2010 1 commit
  3. 26 Sep, 2010 6 commits
  4. 25 Sep, 2010 1 commit
  5. 14 Sep, 2010 2 commits
  6. 13 Sep, 2010 1 commit
  7. 05 Aug, 2010 1 commit
  8. 26 Jul, 2010 3 commits
  9. 23 Jul, 2010 3 commits
  10. 20 Jul, 2010 2 commits
  11. 14 May, 2010 1 commit
  12. 13 May, 2010 8 commits
  13. 12 May, 2010 3 commits
  14. 10 May, 2010 1 commit
  15. 07 May, 2010 1 commit
  16. 16 Mar, 2010 1 commit
  17. 11 Mar, 2010 3 commits
  18. 10 Mar, 2010 1 commit