From: Greg Ames Date: Fri, 27 Jan 2012 21:48:39 +0000 (+0000) Subject: vote for the 2.2.x pregsub patch X-Git-Tag: 2.0.65~92 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=3df898331b4ecb25ac5d15bc63f309ff8c36040d;p=thirdparty%2Fapache%2Fhttpd.git vote for the 2.2.x pregsub patch git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@1236900 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/STATUS b/STATUS index 12631fa7290..e83042ba117 100644 --- a/STATUS +++ b/STATUS @@ -137,6 +137,7 @@ RELEASE SHOWSTOPPERS: Fix integer overflow in ap_pregsub() which, when the mod_setenvif module is enabled, could allow local users to gain privileges via a .htaccess file. [Stefan Fritsch, Greg Ames] + +1: gregames (r1227280 from 2.2.x) *) SECURITY: CVE-2011-4317 (cve.mitre.org) Resolve additional cases of URL rewriting with ProxyPassMatch or