]> git.ipfire.org Git - thirdparty/apache/httpd.git/commitdiff
Propose showstopper fix for httpoxy mitigation
authorWilliam A. Rowe Jr <wrowe@apache.org>
Tue, 26 Jul 2016 16:50:18 +0000 (16:50 +0000)
committerWilliam A. Rowe Jr <wrowe@apache.org>
Tue, 26 Jul 2016 16:50:18 +0000 (16:50 +0000)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1754158 13f79535-47bb-0310-9956-ffa450edef68

STATUS

diff --git a/STATUS b/STATUS
index d1e155c7cfdaafb98c017f6b6947bc7c215df0de..1b651112002f5305ed1d62942bc8a6f47998cb6e 100644 (file)
--- a/STATUS
+++ b/STATUS
@@ -99,6 +99,12 @@ CURRENT RELEASE NOTES:
 
 RELEASE SHOWSTOPPERS:
 
+  *) core: CVE-2016-5387: Mitigate [f]cgi "httpoxy" issues
+      Trunk version of patch:
+         http://svn.apache.org/viewvc?rev=1753228&view=rev
+      Backport version for 2.4.x of patch:
+         Trunk version of patch works (modulo CHANGES)
+      +1: wrowe
 
 PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
   [ start all new proposals below, under PATCHES PROPOSED. ]