]>
git.ipfire.org Git - thirdparty/apache/httpd.git/log
Guenter Knauf [Wed, 14 Sep 2011 11:22:31 +0000 (11:22 +0000)]
Some more NetWare build fixes and improvements.
Added sort function to awk export script to eleminate
need for external sort; removed DAV import file and
generate it now at compile time from headers; moved
some link parameters from commandline to def file.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1170539 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Mon, 12 Sep 2011 16:01:17 +0000 (16:01 +0000)]
Some netWare build tweaks.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1169809 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 12 Sep 2011 02:15:47 +0000 (02:15 +0000)]
RM warning text
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1169596 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Fri, 9 Sep 2011 16:00:43 +0000 (16:00 +0000)]
Update xfers
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167261 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Fri, 9 Sep 2011 15:57:39 +0000 (15:57 +0000)]
bump up
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167260 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Fri, 9 Sep 2011 14:33:52 +0000 (14:33 +0000)]
Add <lowprio20 gmail.com> for regression fix (thx otherbill!)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167215 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Fri, 9 Sep 2011 14:07:38 +0000 (14:07 +0000)]
CVE-2011-3192
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167184 13f79535 -47bb-0310-9956-
ffa450edef68
Jim Jagielski [Fri, 9 Sep 2011 14:02:30 +0000 (14:02 +0000)]
checked ok
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167175 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 9 Sep 2011 13:05:38 +0000 (13:05 +0000)]
Looks great, thanks Jeff!
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167145 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Fri, 9 Sep 2011 11:02:41 +0000 (11:02 +0000)]
try to herd some cats
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1167091 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Thu, 5 May 2011 13:36:58 +0000 (13:36 +0000)]
Add BSD-specific note about core dumping. (Via mi+apache aldan.algebra.com)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1099788 13f79535 -47bb-0310-9956-
ffa450edef68
Roy T. Fielding [Tue, 3 May 2011 20:15:58 +0000 (20:15 +0000)]
sync with trunk
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1099227 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 8 Apr 2011 14:44:02 +0000 (14:44 +0000)]
hernan gonzalez <hgonzalez gmail.com> points out that the USER_AGENT
strings were probably more accurate with the leading ^ anchor.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1090280 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 8 Apr 2011 14:32:17 +0000 (14:32 +0000)]
Remove unnecessary anchors in various rewrite examples. Rebuilding other
changes.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1090270 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Tue, 5 Apr 2011 01:53:21 +0000 (01:53 +0000)]
Fixed sysinclude; removed tab.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1088846 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Sun, 20 Mar 2011 21:43:55 +0000 (21:43 +0000)]
Drop obscure 1.3 change backrefs
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1083581 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 20 Mar 2011 18:58:27 +0000 (18:58 +0000)]
Removed dav_get_limit_xml_body() from mod_dav.h.
This was a forgotten prototype hanging around for close
to 11 years where no code for existed (see r85816);
now removed from all branches per wrowe's permission.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1083536 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 2 Mar 2011 22:24:36 +0000 (22:24 +0000)]
Commented NetWare build debug output which breaks make 3.82.
(backport from r789553).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1076438 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Sun, 16 Jan 2011 16:01:53 +0000 (16:01 +0000)]
Rebuilds changes to mod_autoindex.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1059593 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Sun, 16 Jan 2011 15:58:58 +0000 (15:58 +0000)]
Merges changes from trunk as per tid50417
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1059591 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Mon, 3 Jan 2011 15:37:41 +0000 (15:37 +0000)]
Update copyright year.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1054656 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Mon, 3 Jan 2011 13:02:48 +0000 (13:02 +0000)]
Update copyright to 2011
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1054602 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sat, 25 Dec 2010 13:30:01 +0000 (13:30 +0000)]
Removed define obsolete since r96478.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1052780 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sat, 25 Dec 2010 12:56:07 +0000 (12:56 +0000)]
Removed define obsolete since r93260.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1052778 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sat, 25 Dec 2010 12:51:49 +0000 (12:51 +0000)]
Removed define obsolete since r93260.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1052777 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 21 Dec 2010 00:39:44 +0000 (00:39 +0000)]
Need ZLIB_DLL to build correctly for zlib.dll consumed by openssl and deflate
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1051345 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Sat, 18 Dec 2010 03:19:16 +0000 (03:19 +0000)]
new localized message
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1050577 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 21:18:56 +0000 (21:18 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044724 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 21:04:16 +0000 (21:04 +0000)]
grammar fixes
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044720 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 21:02:57 +0000 (21:02 +0000)]
merge translation from trunk
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044719 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 20:38:47 +0000 (20:38 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044712 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 20:31:19 +0000 (20:31 +0000)]
add localized not-yet-translated messages
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044706 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 00:36:46 +0000 (00:36 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044555 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 00:31:23 +0000 (00:31 +0000)]
update metafiles
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044554 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 11 Dec 2010 00:20:22 +0000 (00:20 +0000)]
merge directive output changes from 2.2
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1044550 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Thu, 9 Dec 2010 14:31:18 +0000 (14:31 +0000)]
Typo correction, from Eduardo Tompson Pereira
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1043976 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 3 Dec 2010 15:08:09 +0000 (15:08 +0000)]
update transformations.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1041852 13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 3 Dec 2010 15:07:41 +0000 (15:07 +0000)]
update for sync with English doc.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1041850 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Mon, 22 Nov 2010 21:07:31 +0000 (21:07 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1037890 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 12 Nov 2010 21:54:51 +0000 (21:54 +0000)]
s/mycompany.com/example.com/g
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1034582 13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 6 Nov 2010 13:48:17 +0000 (13:48 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1032054 13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Fri, 29 Oct 2010 15:28:49 +0000 (15:28 +0000)]
Merge r1028797, r1028799 from trunk:
Add a note about LimitRequest* and name-based vhosts as followup on PR#7741
make the name-based vhost note a warning based on offline discussion with Rich
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1028803 13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Fri, 29 Oct 2010 14:49:09 +0000 (14:49 +0000)]
Add correct context for LimitRequest* as per bug #7741
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1028781 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 19 Oct 2010 19:29:30 +0000 (19:29 +0000)]
Done and away
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1024371 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 18 Oct 2010 16:45:27 +0000 (16:45 +0000)]
Belated Copyright bump
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1023896 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Mon, 18 Oct 2010 09:13:55 +0000 (09:13 +0000)]
Fixed copyright year.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1023697 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 18 Oct 2010 06:42:04 +0000 (06:42 +0000)]
Very minor change required to correctly nmake install the win32 package
from source
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1023663 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 14 Oct 2010 16:36:36 +0000 (16:36 +0000)]
Bump after tag.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1022607 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 14 Oct 2010 16:32:55 +0000 (16:32 +0000)]
Prepare for tag
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1022601 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 14 Oct 2010 16:25:41 +0000 (16:25 +0000)]
Re-./build all for .64 tag
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1022600 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Sat, 9 Oct 2010 10:08:00 +0000 (10:08 +0000)]
zlib 1.1.4/openssl 0.9.7 cannot be sustained, period. bump.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1006128 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 7 Oct 2010 22:29:47 +0000 (22:29 +0000)]
Fix recursive ErrorDocument handling, when r->status isn't HTTP_OK
upon first pass through ap_die().
PR: 36090
Backport: r354118
Submitted by: Chris Darroch
Reviewed by: covener, rjung, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1005656 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 7 Oct 2010 22:24:15 +0000 (22:24 +0000)]
SECURITY: CVE-2010-1452 (cve.mitre.org)
mod_dav: Fix Handling of requests without a path segment.
(mod_cache and mod_session portions don't apply to 2.0.x)
PR: 49246
Backports: r966348
Submitted by: Mark Drayton, trawick
Reviewed by: wrowe, rjung
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1005655 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Wed, 6 Oct 2010 12:04:07 +0000 (12:04 +0000)]
Fix description of proposal (copy&paste error).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004999 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:35:12 +0000 (10:35 +0000)]
Fixed mod_expires: Expires time shouldn't be in the past.
r1002205 in test framework needs to be reverted now since this is fixed.
Author: rjung, reviewed by: wrowe, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004974 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:30:11 +0000 (10:30 +0000)]
PR 33112 - Fix for query string preservation after content negotiation.
r1002165 in test framework needs to be revertet now since this is fixed.
Author rjung, reviewed by wrowe, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004972 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:24:18 +0000 (10:24 +0000)]
Modified rotatelogs to behave the same as the core log writer.
Author wrowe, reviewed by rjung, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004971 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:18:15 +0000 (10:18 +0000)]
Rename macro to a better name and sync with trunk.
Reviewed by wrowe, rjung.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004969 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Tue, 5 Oct 2010 20:52:18 +0000 (20:52 +0000)]
promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004810 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Tue, 5 Oct 2010 20:49:37 +0000 (20:49 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004809 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 5 Oct 2010 19:39:01 +0000 (19:39 +0000)]
Promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004787 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 5 Oct 2010 19:38:04 +0000 (19:38 +0000)]
Vote, remove comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004785 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 5 Oct 2010 18:01:16 +0000 (18:01 +0000)]
Votes, promote, note intent to tag Thursday
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004740 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:34:35 +0000 (00:34 +0000)]
propose backport.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002915 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:17:12 +0000 (00:17 +0000)]
removed default setting since no longer needed.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002907 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:05:50 +0000 (00:05 +0000)]
enabled building gen_test_char for running on build when cross-compiling;
this does not change code for any platform unless CROSS_COMPILE is defined.
Backport of r795971 - reviewed by trawick, rjung.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002901 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:02:02 +0000 (00:02 +0000)]
promote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002899 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Wed, 29 Sep 2010 15:05:12 +0000 (15:05 +0000)]
Vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002665 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 29 Sep 2010 02:16:10 +0000 (02:16 +0000)]
Added comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002449 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 17:09:44 +0000 (17:09 +0000)]
Vote, comment, propose.
The new proposals fix previous test framework
failures. Those tests are disabled for 2.0 right now.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002266 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 15:59:13 +0000 (15:59 +0000)]
Merge revisions 906039, 906057, 906485, 906491, 908015, 916733, 916817
from trunk resp. 917044 from 2.2.x:
New releases of OpenSSL will only allow secure renegotiation by
default. Add an "SSLInsecureRenegotiation" directive to enable
renegotiation against unpatched clients, to ease transition.
Submitted by: jorton
Backport by: rjung
Reviewed by: pgollucci, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002233 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 15:49:07 +0000 (15:49 +0000)]
Merge r891282 from trunk resp. 896900 from 2.2.x:
Further mitigation for the TLS renegotation attack, CVE-2009-3555:
* modules/ssl/ssl_engine_kernel.c (has_buffered_data): New function.
(ssl_hook_Access): Forcibly disable keepalive for the connection if
there is any buffered data readable from the input filter stack.
* modules/ssl/ssl_engine_io.c (ssl_io_filter_input): Ensure that the
BIO uses blocking operations when invoked outside direct control of
the httpd filter stack.
Thanks to Hartmut Keil <Hartmut.Keil adnovum.ch> for proposing this
technique.
Submitted by: jorton
Backport by: rjung
Reviewed by: pgollucci, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002227 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Mon, 27 Sep 2010 14:42:00 +0000 (14:42 +0000)]
backport trunk r683280
mod_ssl: Use memmove instead of memcpy for overlapping buffers
Submitted by: jorton
Reviewed by: sf, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001762 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:33:22 +0000 (13:33 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001426 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:30:22 +0000 (13:30 +0000)]
backport r791454 from 2.2.x branch:
SECURITY: CVE-2009-1891 (cve.mitre.org)
Fix a potential Denial-of-Service attack against mod_deflate or other
modules, by forcing the server to consume CPU time in compressing a
large file after a client disconnects. [Joe Orton, Ruediger Pluem]
Submitted by: jorton, rpluem
Reviewed by: pgollucci, poirier, rjung
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001425 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:07:15 +0000 (13:07 +0000)]
vote+promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001424 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 26 Sep 2010 10:19:46 +0000 (10:19 +0000)]
Removed a tab and trailing spaces; no code change.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001403 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 26 Sep 2010 09:28:51 +0000 (09:28 +0000)]
prepare NetWare build for creating build helpers to run on build platform;
disabled by default until gen_test_char.c is modified to allow for cross-compile.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001396 13f79535 -47bb-0310-9956-
ffa450edef68
Joe Orton [Sun, 26 Sep 2010 08:48:40 +0000 (08:48 +0000)]
Vote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001392 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Sat, 25 Sep 2010 19:53:46 +0000 (19:53 +0000)]
propose
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001311 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 14 Sep 2010 07:15:29 +0000 (07:15 +0000)]
Vote and correct classification of another accepted patch
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996770
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 14 Sep 2010 02:58:04 +0000 (02:58 +0000)]
Elevate this to a showstopper, 2.0.64 should not occur without, as noted
by trawick.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996743
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 13 Sep 2010 23:03:47 +0000 (23:03 +0000)]
Promote, demote. Please look at this specific patch if you care that it just hit the 'going nowhere' category
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996719
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 5 Aug 2010 17:41:00 +0000 (17:41 +0000)]
get the CVE-2010-1452 fix in patches/apply_to_xxx into svn
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@982705
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Mon, 26 Jul 2010 10:58:00 +0000 (10:58 +0000)]
Add proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979237
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 26 Jul 2010 07:42:48 +0000 (07:42 +0000)]
update transformations.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979187
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 26 Jul 2010 07:40:35 +0000 (07:40 +0000)]
update for sync with English docs.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979186
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 04:04:29 +0000 (04:04 +0000)]
Applied accepted backport 164538.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966953
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 03:49:09 +0000 (03:49 +0000)]
Add backport proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966949
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 00:40:00 +0000 (00:40 +0000)]
Cleaned up NetWare makefiles:
- removed obsolete -prefix compiler switch since already defined global for all files
- removed obsolete include paths
- changed include paths to use internal vars so hat apr/apr-util builds outside source tree
- removed trailing tabs and spaces, other minor cosmetic changes
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966915
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 20 Jul 2010 11:07:01 +0000 (11:07 +0000)]
Replace "back-slash" with "backslash" in docs.
I kept "back slash" when explicitely used in
comparison with "forward slash".
Backport of r965792 from trunk and of r965799
from 2.2.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@965803
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 20 Jul 2010 11:02:16 +0000 (11:02 +0000)]
Fix typo in rewrite docs (slash -> backslash).
Thanks to Denis Howe for the hint.
PR49620.
Backport of r965798 from 2.2.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@965801
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Fri, 14 May 2010 09:12:00 +0000 (09:12 +0000)]
Remove obsolete reference to patch which has already
been committed.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@944165
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 19:18:50 +0000 (19:18 +0000)]
merge r814045 from trunk (2.2.x rev 814847):
CVE-2009-3095: mod_proxy_ftp sanity check authn credentials.
Submitted by: Stefan Fritsch <sf fritsch.de>, Joe Orton
Reviewed by: pgollucci, poirier, rjung, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943980
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 19:16:36 +0000 (19:16 +0000)]
the CVE-2009-3095 fix works for me with 2.0.x
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943977
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 16:06:25 +0000 (16:06 +0000)]
merge r814844 from 2.2.x branch (trunk revs 814652 and 814785):
*) SECURITY: CVE-2009-3094 (cve.mitre.org)
mod_proxy_ftp: NULL pointer dereference on error paths.
[Stefan Fritsch <sf fritsch.de>, Joe Orton]
Reviewed by: pgollucci, poirier, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943925
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 16:00:37 +0000 (16:00 +0000)]
CVE-2009-3094 patch fixes crash for me
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943923
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:47:34 +0000 (13:47 +0000)]
Promote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943882
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:46:21 +0000 (13:46 +0000)]
Vote, comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943880
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:27:03 +0000 (13:27 +0000)]
Merge r833582, r833593, r881222 from trunk:
SECURITY: Partial fix for CVE-2009-3555:
Reject client-initiated renegotiations; this is sufficient to prevent
the attack for any configuration which does not require renegotiation
due to per-directory/per-location access control configuration.
Configuration with per-directory/per-location access control
requirements (such as "SSLVerifyClient require") are still vulnerable
to CVE-2009-3555 with this patch applied (if using OpenSSL != 0.9.8l).
* modules/ssl/ssl_private.h (SSLConnRec): Add reneg_state field.
(ssl_callback_Info): Renamed from ssl_callback_LogTracingState.
* modules/ssl/ssl_engine_init.c (ssl_init_ctx_callbacks): Install
the (renamed) info callback unconditionally.
* modules/ssl/ssl_engine_io.c (ssl_filter_ctx_t): Add config pointer
to SSLConnRec.
(bio_filter_out_write, bio_filter_in_read): Fail with
APR_ECONNABORTED if the reneg state is set to RENEG_ABORT.
* modules/ssl/ssl_engine_kernel.c (log_tracing_state): Factored out
of ssl_callback_LogTracingState.
(ssl_callback_Info): New function.
Submitted by: jorton, rpluem, rjung
Reviewed by: rjung, rpluem, pgollucci
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943879
13f79535 -47bb-0310-9956-
ffa450edef68