From: Eric Covener Date: Thu, 17 Jul 2014 22:45:50 +0000 (+0000) Subject: drop CVE-2014-0117 proposal, 2.2 not affected X-Git-Tag: 2.2.28~29 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=bd39158877bde82c095c83db366da2b78a65e965;p=thirdparty%2Fapache%2Fhttpd.git drop CVE-2014-0117 proposal, 2.2 not affected git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1611499 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/STATUS b/STATUS index 5c5b210d973..f87e26faff3 100644 --- a/STATUS +++ b/STATUS @@ -99,18 +99,6 @@ RELEASE SHOWSTOPPERS: PATCHES ACCEPTED TO BACKPORT FROM TRUNK: [ start all new proposals below, under PATCHES PROPOSED. ] - * SECURITY: CVE-2014-0117 (cve.mitre.org) - Fix crashing with mod_proxy Connection handling. - trunk patch: http://svn.apache.org/r1610674 - 2.4.x patch: http://svn.apache.org/r1610737 (simplified ver) - 2.2.x patch: 2.4 works - +1: - -1: jorton: patch does not apply (or should not, though "svn merge" works), - the code in 2.2.x looks safe by eyeball and testing. - covener: +1 for N/A CVE -- no ap_get_token() in this path for 2.2.x - ylavic: indeed, +1 for N/A - wrowe: echo covener, +1, and +1 for CVE N/A - PATCHES PROPOSED TO BACKPORT FROM TRUNK: [ New proposals should be added at the end of the list ]