From: Ruediger Pluem Date: Sat, 29 Dec 2007 09:31:12 +0000 (+0000) Subject: * Promote X-Git-Tag: 2.2.7~49 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=101fbccc7a7c716d598e410e0fe6e7d6b5e64bf9;p=thirdparty%2Fapache%2Fhttpd.git * Promote git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@607406 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/STATUS b/STATUS index 17c02bec9fc..1f22efcc4f4 100644 --- a/STATUS +++ b/STATUS @@ -89,14 +89,6 @@ RELEASE SHOWSTOPPERS: or all RFC conformant browsers, and additional customization can come as a new feature in the future. - * mod_status: Ensure refresh parameter is numeric to prevent a possible XSS - attack caused by redirecting to other URLs. - Trunk version of patch: - http://svn.apache.org/viewvc?rev=607282&view=rev - Backport version for 2.0.x of patch: - http://awe.com/e8f6ad05238f8/CVE-2007-6388-httpd-2.x.patch - +1: rpluem, wrowe, jorton - * mod_proxy_balancer: Prevent crash in balancer manager if invalid balancer name is passed as parameter. Trunk version of patch: @@ -120,6 +112,14 @@ RELEASE SHOWSTOPPERS: PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] + * mod_status: Ensure refresh parameter is numeric to prevent a possible XSS + attack caused by redirecting to other URLs. + Trunk version of patch: + http://svn.apache.org/viewvc?rev=607282&view=rev + Backport version for 2.0.x of patch: + http://awe.com/e8f6ad05238f8/CVE-2007-6388-httpd-2.x.patch + +1: rpluem, wrowe, jorton + PATCHES PROPOSED TO BACKPORT FROM TRUNK: [ New proposals should be added at the end of the list ]