Skip to content
  1. Oct 06, 2011
    • Joe Orton's avatar
      Merge r1179239 from trunk: · d239e981
      Joe Orton authored
      SECURITY (CVE-2011-3368): Prevent unintended pattern expansion in some
      reverse proxy configurations by strictly validating the request-URI:
      
      * server/protocol.c (read_request_line): Send a 400 response if the
        request-URI does not match the grammar from RFC 2616.  This ensures
        the input string for RewriteRule et al really is an absolute path.
      
      Reviewed by: jim, covener, rjung
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1179525 13f79535-47bb-0310-9956-ffa450edef68
      d239e981
  2. Oct 05, 2011
  3. Oct 04, 2011
  4. Oct 01, 2011
  5. Sep 29, 2011
  6. Sep 28, 2011
  7. Sep 27, 2011
  8. Sep 26, 2011
  9. Sep 23, 2011
  10. Sep 17, 2011
  11. Sep 14, 2011
  12. Sep 13, 2011
  13. Sep 12, 2011
  14. Sep 11, 2011
  15. Sep 10, 2011