Skip to content
  1. May 13, 2010
    • Rainer Jung's avatar
      Vote, comment. · 8e3dc23f
      Rainer Jung authored
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943880 13f79535-47bb-0310-9956-ffa450edef68
      8e3dc23f
    • Rainer Jung's avatar
      Merge r833582, r833593, r881222 from trunk: · c2078ecc
      Rainer Jung authored
      SECURITY: Partial fix for CVE-2009-3555:
      
      Reject client-initiated renegotiations; this is sufficient to prevent
      the attack for any configuration which does not require renegotiation
      due to per-directory/per-location access control configuration.
      
      Configuration with per-directory/per-location access control
      requirements (such as "SSLVerifyClient require") are still vulnerable
      to CVE-2009-3555 with this patch applied (if using OpenSSL != 0.9.8l).
      
      * modules/ssl/ssl_private.h (SSLConnRec): Add reneg_state field.
        (ssl_callback_Info): Renamed from ssl_callback_LogTracingState.
      
      * modules/ssl/ssl_engine_init.c (ssl_init_ctx_callbacks): Install
        the (renamed) info callback unconditionally.
      
      * modules/ssl/ssl_engine_io.c (ssl_filter_ctx_t): Add config pointer
        to SSLConnRec.
        (bio_filter_out_write, bio_filter_in_read): Fail with
        APR_ECONNABORTED if the reneg state is set to RENEG_ABORT.
      
      * modules/ssl/ssl_engine_kernel.c (log_tracing_state): Factored out
        of ssl_callback_LogTracingState.
        (ssl_callback_Info): New function.
      
      Submitted by: jorton, rpluem, rjung
      Reviewed by: rjung, rpluem, pgollucci
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943879 13f79535-47bb-0310-9956-ffa450edef68
      c2078ecc
    • Daniel Earl Poirier's avatar
      Vote to backport some security fixes. · f12ccb85
      Daniel Earl Poirier authored
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943869 13f79535-47bb-0310-9956-ffa450edef68
      f12ccb85
  2. May 12, 2010
  3. May 10, 2010
  4. May 07, 2010
  5. Mar 16, 2010
  6. Mar 11, 2010
  7. Mar 10, 2010
  8. Mar 09, 2010
  9. Jan 15, 2010
  10. Jan 11, 2010
  11. Jan 05, 2010
  12. Dec 22, 2009
  13. Dec 20, 2009
  14. Dec 14, 2009
  15. Dec 12, 2009
  16. Dec 03, 2009
  17. Nov 21, 2009
  18. Nov 20, 2009
  19. Oct 17, 2009
  20. Sep 20, 2009
  21. Sep 02, 2009
  22. Aug 03, 2009
  23. Jul 03, 2009