1. 06 Oct, 2011 1 commit
    • Joe Orton's avatar
      Merge r1179239 from trunk: · d239e981
      Joe Orton authored
      SECURITY (CVE-2011-3368): Prevent unintended pattern expansion in some
      reverse proxy configurations by strictly validating the request-URI:
      
      * server/protocol.c (read_request_line): Send a 400 response if the
        request-URI does not match the grammar from RFC 2616.  This ensures
        the input string for RewriteRule et al really is an absolute path.
      
      Reviewed by: jim, covener, rjung
      
      
      git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1179525 13f79535-47bb-0310-9956-ffa450edef68
      d239e981
  2. 05 Oct, 2011 7 commits
  3. 04 Oct, 2011 1 commit
  4. 01 Oct, 2011 4 commits
  5. 29 Sep, 2011 6 commits
  6. 28 Sep, 2011 6 commits
  7. 27 Sep, 2011 4 commits
  8. 26 Sep, 2011 2 commits
  9. 23 Sep, 2011 1 commit
  10. 17 Sep, 2011 1 commit
  11. 14 Sep, 2011 3 commits
  12. 13 Sep, 2011 1 commit
  13. 12 Sep, 2011 1 commit
  14. 11 Sep, 2011 1 commit
  15. 10 Sep, 2011 1 commit