From: Joe Orton Date: Fri, 29 Jun 2007 17:05:59 +0000 (+0000) Subject: Propose two. X-Git-Tag: 2.0.60~30 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=7bcd7f7c728e7e05c3282e96dc9e3343267ae045;p=thirdparty%2Fapache%2Fhttpd.git Propose two. git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@551960 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/STATUS b/STATUS index 779ec89abd7..b7dd7e49f5f 100644 --- a/STATUS +++ b/STATUS @@ -146,6 +146,21 @@ PATCHES PROPOSED TO BACKPORT FROM TRUNK: http://svn.apache.org/viewvc?view=rev&rev=520733 +1: wrowe + * SECURITY: CVE-2007-3304 + scoreboard pid protection fixes -- the only fix for 2.0.x is + to ensure a valid positive pid is passed to apr_proc_wait(); + the MPMs do not kill children directly as in 2.2.x. + trunk commit: + http://svn.apache.org/viewvc?view=rev&rev=551843 + patch for 2.0.x: + http://people.apache.org/~jorton/httpd-2.0.x-CVE-2007-3304.patch + +1: jorton + + * SECURITY: CVE-2006-5752 + mod_status XSS fix for broken browsers: + http://svn.apache.org/viewvc?view=rev&rev=549159 + +1: jorton + PATCHES TO BACKPORT THAT ARE ON HOLD OR NOT GOING ANYWHERE SOON: *) mod_headers: Support {...}s tag for SSL variable lookup.