Skip to content
  1. Oct 18, 2000
    • Tony Finch's avatar
      Tighten up the syntax checking of Host: headers to fix a · 7b2aa25b
      Tony Finch authored
      security bug in some mass virtual hosting configurations
      that can allow a remote attacker to retrieve some files
      on the system that should be inaccessible. The problem
      occured with requests including the line "Host: ..." --
      the last dot is stripped and the remaining ".." then
      reveals a parent directory.
      
      Reported by: Peter Christoffersen <pch@mindpass.com>
      Message-ID: <8quts6$2el$1@news.inet.tele.dk>
      Newsgroups: comp.infosystems.www.servers.unix
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@86637 13f79535-47bb-0310-9956-ffa450edef68
      7b2aa25b
  2. Oct 17, 2000
  3. Oct 16, 2000
  4. Oct 15, 2000
  5. Oct 14, 2000