PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
[ start all new proposals below, under PATCHES PROPOSED. ]
-
-PATCHES PROPOSED TO BACKPORT FROM TRUNK:
- [ New proposals should be added at the end of the list ]
-
-
* SECURITY: CVE-2014-0118 (cve.mitre.org)
mod_deflate: The DEFLATE input filter (inflates request bodies) now
limits the length and compression ratio of inflated request bodies to avoid
trunk patch: http://svn.apache.org/r1610501
2.2.x patch: http://people.apache.org/~covener/patches/httpd-2.2.x-deflate_limitrequestbody.diff
- +1: covener, ylavic
+ +1: covener, ylavic, jorton
* SECURITY: CVE-2014-0117 (cve.mitre.org)
trunk patch: http://svn.apache.org/r1610674
2.4.x patch: http://svn.apache.org/r1610737 (simplified ver)
2.2.x patch: 2.4 works
- +1: covener, ylavic
+ +1: covener, ylavic, jorton
+
+PATCHES PROPOSED TO BACKPORT FROM TRUNK:
+ [ New proposals should be added at the end of the list ]
+
* mod_proxy: Don't reuse a SSL backend connection whose SNI differs. PR 55782.
This may happen when ProxyPreserveHost is on and the proxy-worker