]>
git.ipfire.org Git - thirdparty/apache/httpd.git/log
William A. Rowe Jr [Thu, 7 Oct 2010 22:29:47 +0000 (22:29 +0000)]
Fix recursive ErrorDocument handling, when r->status isn't HTTP_OK
upon first pass through ap_die().
PR: 36090
Backport: r354118
Submitted by: Chris Darroch
Reviewed by: covener, rjung, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1005656 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Thu, 7 Oct 2010 22:24:15 +0000 (22:24 +0000)]
SECURITY: CVE-2010-1452 (cve.mitre.org)
mod_dav: Fix Handling of requests without a path segment.
(mod_cache and mod_session portions don't apply to 2.0.x)
PR: 49246
Backports: r966348
Submitted by: Mark Drayton, trawick
Reviewed by: wrowe, rjung
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1005655 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Wed, 6 Oct 2010 12:04:07 +0000 (12:04 +0000)]
Fix description of proposal (copy&paste error).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004999 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:35:12 +0000 (10:35 +0000)]
Fixed mod_expires: Expires time shouldn't be in the past.
r1002205 in test framework needs to be reverted now since this is fixed.
Author: rjung, reviewed by: wrowe, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004974 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:30:11 +0000 (10:30 +0000)]
PR 33112 - Fix for query string preservation after content negotiation.
r1002165 in test framework needs to be revertet now since this is fixed.
Author rjung, reviewed by wrowe, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004972 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:24:18 +0000 (10:24 +0000)]
Modified rotatelogs to behave the same as the core log writer.
Author wrowe, reviewed by rjung, sf.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004971 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 6 Oct 2010 10:18:15 +0000 (10:18 +0000)]
Rename macro to a better name and sync with trunk.
Reviewed by wrowe, rjung.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004969 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Tue, 5 Oct 2010 20:52:18 +0000 (20:52 +0000)]
promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004810 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Tue, 5 Oct 2010 20:49:37 +0000 (20:49 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004809 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 5 Oct 2010 19:39:01 +0000 (19:39 +0000)]
Promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004787 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 5 Oct 2010 19:38:04 +0000 (19:38 +0000)]
Vote, remove comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004785 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 5 Oct 2010 18:01:16 +0000 (18:01 +0000)]
Votes, promote, note intent to tag Thursday
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1004740 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:34:35 +0000 (00:34 +0000)]
propose backport.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002915 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:17:12 +0000 (00:17 +0000)]
removed default setting since no longer needed.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002907 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:05:50 +0000 (00:05 +0000)]
enabled building gen_test_char for running on build when cross-compiling;
this does not change code for any platform unless CROSS_COMPILE is defined.
Backport of r795971 - reviewed by trawick, rjung.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002901 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Thu, 30 Sep 2010 00:02:02 +0000 (00:02 +0000)]
promote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002899 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Wed, 29 Sep 2010 15:05:12 +0000 (15:05 +0000)]
Vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002665 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Wed, 29 Sep 2010 02:16:10 +0000 (02:16 +0000)]
Added comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002449 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 17:09:44 +0000 (17:09 +0000)]
Vote, comment, propose.
The new proposals fix previous test framework
failures. Those tests are disabled for 2.0 right now.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002266 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 15:59:13 +0000 (15:59 +0000)]
Merge revisions 906039, 906057, 906485, 906491, 908015, 916733, 916817
from trunk resp. 917044 from 2.2.x:
New releases of OpenSSL will only allow secure renegotiation by
default. Add an "SSLInsecureRenegotiation" directive to enable
renegotiation against unpatched clients, to ease transition.
Submitted by: jorton
Backport by: rjung
Reviewed by: pgollucci, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002233 13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 28 Sep 2010 15:49:07 +0000 (15:49 +0000)]
Merge r891282 from trunk resp. 896900 from 2.2.x:
Further mitigation for the TLS renegotation attack, CVE-2009-3555:
* modules/ssl/ssl_engine_kernel.c (has_buffered_data): New function.
(ssl_hook_Access): Forcibly disable keepalive for the connection if
there is any buffered data readable from the input filter stack.
* modules/ssl/ssl_engine_io.c (ssl_io_filter_input): Ensure that the
BIO uses blocking operations when invoked outside direct control of
the httpd filter stack.
Thanks to Hartmut Keil <Hartmut.Keil adnovum.ch> for proposing this
technique.
Submitted by: jorton
Backport by: rjung
Reviewed by: pgollucci, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1002227 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Mon, 27 Sep 2010 14:42:00 +0000 (14:42 +0000)]
backport trunk r683280
mod_ssl: Use memmove instead of memcpy for overlapping buffers
Submitted by: jorton
Reviewed by: sf, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001762 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:33:22 +0000 (13:33 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001426 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:30:22 +0000 (13:30 +0000)]
backport r791454 from 2.2.x branch:
SECURITY: CVE-2009-1891 (cve.mitre.org)
Fix a potential Denial-of-Service attack against mod_deflate or other
modules, by forcing the server to consume CPU time in compressing a
large file after a client disconnects. [Joe Orton, Ruediger Pluem]
Submitted by: jorton, rpluem
Reviewed by: pgollucci, poirier, rjung
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001425 13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Sun, 26 Sep 2010 13:07:15 +0000 (13:07 +0000)]
vote+promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001424 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 26 Sep 2010 10:19:46 +0000 (10:19 +0000)]
Removed a tab and trailing spaces; no code change.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001403 13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Sun, 26 Sep 2010 09:28:51 +0000 (09:28 +0000)]
prepare NetWare build for creating build helpers to run on build platform;
disabled by default until gen_test_char.c is modified to allow for cross-compile.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001396 13f79535 -47bb-0310-9956-
ffa450edef68
Joe Orton [Sun, 26 Sep 2010 08:48:40 +0000 (08:48 +0000)]
Vote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001392 13f79535 -47bb-0310-9956-
ffa450edef68
Stefan Fritsch [Sat, 25 Sep 2010 19:53:46 +0000 (19:53 +0000)]
propose
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@
1001311 13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 14 Sep 2010 07:15:29 +0000 (07:15 +0000)]
Vote and correct classification of another accepted patch
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996770
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 14 Sep 2010 02:58:04 +0000 (02:58 +0000)]
Elevate this to a showstopper, 2.0.64 should not occur without, as noted
by trawick.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996743
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Mon, 13 Sep 2010 23:03:47 +0000 (23:03 +0000)]
Promote, demote. Please look at this specific patch if you care that it just hit the 'going nowhere' category
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@996719
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 5 Aug 2010 17:41:00 +0000 (17:41 +0000)]
get the CVE-2010-1452 fix in patches/apply_to_xxx into svn
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@982705
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Mon, 26 Jul 2010 10:58:00 +0000 (10:58 +0000)]
Add proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979237
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 26 Jul 2010 07:42:48 +0000 (07:42 +0000)]
update transformations.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979187
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 26 Jul 2010 07:40:35 +0000 (07:40 +0000)]
update for sync with English docs.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@979186
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 04:04:29 +0000 (04:04 +0000)]
Applied accepted backport 164538.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966953
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 03:49:09 +0000 (03:49 +0000)]
Add backport proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966949
13f79535 -47bb-0310-9956-
ffa450edef68
Guenter Knauf [Fri, 23 Jul 2010 00:40:00 +0000 (00:40 +0000)]
Cleaned up NetWare makefiles:
- removed obsolete -prefix compiler switch since already defined global for all files
- removed obsolete include paths
- changed include paths to use internal vars so hat apr/apr-util builds outside source tree
- removed trailing tabs and spaces, other minor cosmetic changes
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@966915
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 20 Jul 2010 11:07:01 +0000 (11:07 +0000)]
Replace "back-slash" with "backslash" in docs.
I kept "back slash" when explicitely used in
comparison with "forward slash".
Backport of r965792 from trunk and of r965799
from 2.2.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@965803
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 20 Jul 2010 11:02:16 +0000 (11:02 +0000)]
Fix typo in rewrite docs (slash -> backslash).
Thanks to Denis Howe for the hint.
PR49620.
Backport of r965798 from 2.2.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@965801
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Fri, 14 May 2010 09:12:00 +0000 (09:12 +0000)]
Remove obsolete reference to patch which has already
been committed.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@944165
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 19:18:50 +0000 (19:18 +0000)]
merge r814045 from trunk (2.2.x rev 814847):
CVE-2009-3095: mod_proxy_ftp sanity check authn credentials.
Submitted by: Stefan Fritsch <sf fritsch.de>, Joe Orton
Reviewed by: pgollucci, poirier, rjung, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943980
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 19:16:36 +0000 (19:16 +0000)]
the CVE-2009-3095 fix works for me with 2.0.x
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943977
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 16:06:25 +0000 (16:06 +0000)]
merge r814844 from 2.2.x branch (trunk revs 814652 and 814785):
*) SECURITY: CVE-2009-3094 (cve.mitre.org)
mod_proxy_ftp: NULL pointer dereference on error paths.
[Stefan Fritsch <sf fritsch.de>, Joe Orton]
Reviewed by: pgollucci, poirier, trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943925
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 13 May 2010 16:00:37 +0000 (16:00 +0000)]
CVE-2009-3094 patch fixes crash for me
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943923
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:47:34 +0000 (13:47 +0000)]
Promote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943882
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:46:21 +0000 (13:46 +0000)]
Vote, comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943880
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Thu, 13 May 2010 13:27:03 +0000 (13:27 +0000)]
Merge r833582, r833593, r881222 from trunk:
SECURITY: Partial fix for CVE-2009-3555:
Reject client-initiated renegotiations; this is sufficient to prevent
the attack for any configuration which does not require renegotiation
due to per-directory/per-location access control configuration.
Configuration with per-directory/per-location access control
requirements (such as "SSLVerifyClient require") are still vulnerable
to CVE-2009-3555 with this patch applied (if using OpenSSL != 0.9.8l).
* modules/ssl/ssl_private.h (SSLConnRec): Add reneg_state field.
(ssl_callback_Info): Renamed from ssl_callback_LogTracingState.
* modules/ssl/ssl_engine_init.c (ssl_init_ctx_callbacks): Install
the (renamed) info callback unconditionally.
* modules/ssl/ssl_engine_io.c (ssl_filter_ctx_t): Add config pointer
to SSLConnRec.
(bio_filter_out_write, bio_filter_in_read): Fail with
APR_ECONNABORTED if the reneg state is set to RENEG_ABORT.
* modules/ssl/ssl_engine_kernel.c (log_tracing_state): Factored out
of ssl_callback_LogTracingState.
(ssl_callback_Info): New function.
Submitted by: jorton, rpluem, rjung
Reviewed by: rjung, rpluem, pgollucci
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943879
13f79535 -47bb-0310-9956-
ffa450edef68
Daniel Earl Poirier [Thu, 13 May 2010 11:56:37 +0000 (11:56 +0000)]
Vote to backport some security fixes.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943869
13f79535 -47bb-0310-9956-
ffa450edef68
Philip M. Gollucci [Wed, 12 May 2010 23:31:04 +0000 (23:31 +0000)]
promote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943750
13f79535 -47bb-0310-9956-
ffa450edef68
Philip M. Gollucci [Wed, 12 May 2010 23:28:53 +0000 (23:28 +0000)]
vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943749
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Wed, 12 May 2010 18:08:31 +0000 (18:08 +0000)]
propose backporting a few security fixes to the 2.0.x branch
I haven't properly reviewed/tested these yet myself, but I'd guess
that some among us may be in a good position to review. (And I
should get to it eventually.)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@943603
13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Mon, 10 May 2010 22:45:57 +0000 (22:45 +0000)]
Line breaks to make example useful.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@942939
13f79535 -47bb-0310-9956-
ffa450edef68
Philip M. Gollucci [Fri, 7 May 2010 20:43:34 +0000 (20:43 +0000)]
- Backports r942209
ix the following:
$> grep -e autoindex_ -e cgi_ httpd.conf
LoadModule autoindex_module libexec/apache22/mod_autoindex.so
LoadModule cgi_module libexec/apache22/mod_cgi.so
fire up the following commands
$> apxs -e -a -n autoindex mod_autoindex.so
[activating module `autoindex' in /usr/local/etc/apache22/httpd.conf]
$> apxs -e -a -n cgi mod_cgi.so
[activating module `cgi' in /usr/local/etc/apache22/httpd.conf]
This will result into the following httpd.conf
$> grep -e autoindex_ -e cgi_ httpd.conf
LoadModule autoindex_module libexec/apache22/mod_autoindex.so
LoadModule cgi_module libexec/apache22/mod_cgi.so
LoadModule autoindex_module libexec/apache22/mod_autoindex.so
LoadModule cgi_module libexec/apache22/mod_cgi.so
As you notice the modules are now loaded twice
Now try to deactivate for the loaded ssl module
$> grep ssl_ httpd.conf
LoadModule ssl_module libexec/apache22/mod_ssl.so
$> apxs -e -A -n ssl mod_ssl.so
[preparing module `ssl' in /usr/local/etc/apache22/httpd.conf]
$> grep ssl_ httpd.conf
LoadModule ssl_module libexec/apache22/mod_ssl.so
#LoadModule ssl_module libexec/apache22/mod_ssl.so
As reported in FreeBSD ports PR: http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/133704
Previously discussed with: wrowe@
This b/c '$lmd' expects the amount of space to be a fixed amount. Use \s+ to make
any valid httpd.conf syntax work (i.e. at least 1 space)
As previously discussed with wrowe, treast this the same way roy treats
mime.types
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@942211
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Tue, 16 Mar 2010 15:16:41 +0000 (15:16 +0000)]
Add proposal to backport SSLInsecureRenegotiation
to 2.0.x.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@923801
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 11 Mar 2010 15:57:26 +0000 (15:57 +0000)]
merge from trunk and 2.2.x:
SECURITY: CVE-2010-0434 (cve.mitre.org)
Ensure each subrequest has a shallow copy of headers_in so that the
parent request headers are not corrupted. Elimiates a problematic
optimization in the case of no request body.
PR: 48359
Submitted by: Jake Scott, William Rowe, Ruediger Pluem
Reviewed by: wrowe, trawick, rpluem
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921910
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Thu, 11 Mar 2010 15:54:18 +0000 (15:54 +0000)]
merge from trunk and 2.2.x, using existing published patch for 2.0.63:
*) SECURITY: CVE-2008-2364 (cve.mitre.org)
mod_proxy_http: Better handling of excessive interim responses
from origin server to prevent potential denial of service and high
memory usage. Reported by Ryujiro Shibuya. [Ruediger Pluem,
Joe Orton, Jim Jagielski]
Reviewed by: trawick, wrowe, rpluem
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921908
13f79535 -47bb-0310-9956-
ffa450edef68
Ruediger Pluem [Thu, 11 Mar 2010 13:24:41 +0000 (13:24 +0000)]
* Vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921839
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Wed, 10 Mar 2010 11:03:57 +0000 (11:03 +0000)]
+1 for apr_table_copy()
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921303
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 9 Mar 2010 21:52:20 +0000 (21:52 +0000)]
Yes, reverting prematurely applied backport
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921146
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 9 Mar 2010 21:51:10 +0000 (21:51 +0000)]
Add CVE-2010-0434 fix for consideration
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921143
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 9 Mar 2010 19:52:51 +0000 (19:52 +0000)]
Revert; been so long since I've worked in 2.0 svn, forgot the hazard map
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921086
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 9 Mar 2010 19:51:11 +0000 (19:51 +0000)]
Very sensible.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921081
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Tue, 9 Mar 2010 17:35:05 +0000 (17:35 +0000)]
I'd prefer that patches in patches/apply_to_2.0.* get committed
to the 2.0.x branch for now.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@921002
13f79535 -47bb-0310-9956-
ffa450edef68
Jeff Trawick [Tue, 9 Mar 2010 17:29:22 +0000 (17:29 +0000)]
follow up r920961 with the related CHANGES entry
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@920995
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Tue, 9 Mar 2010 16:21:12 +0000 (16:21 +0000)]
SECURITY: CVE-2010-0425 (cve.mitre.org)
mod_isapi: Do not unload an isapi .dll module until the request
processing is completed, avoiding orphaned callback pointers.
Submitted by: Brett Gervasoni <brettg senseofsecurity.com>, trawick
Reviewed by: trawick, wrowe
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@920961
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 15 Jan 2010 20:01:50 +0000 (20:01 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@899795
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 15 Jan 2010 20:01:19 +0000 (20:01 +0000)]
update for sync with English docs.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@899794
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Mon, 11 Jan 2010 09:10:52 +0000 (09:10 +0000)]
Sorry, wrong URL.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@897806
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Mon, 11 Jan 2010 09:08:35 +0000 (09:08 +0000)]
Add proposal.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@897805
13f79535 -47bb-0310-9956-
ffa450edef68
Roy T. Fielding [Tue, 5 Jan 2010 23:50:35 +0000 (23:50 +0000)]
Merge from trunk r896223: Update for IANA and comment-out unused types.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@896280
13f79535 -47bb-0310-9956-
ffa450edef68
Takashi Sato [Tue, 22 Dec 2009 17:28:06 +0000 (17:28 +0000)]
Fix a mistranslation.
Submitted by: HANAWA Yoshio <hanawa dino.co.jp>
Reviewed by: takashi
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@893242
13f79535 -47bb-0310-9956-
ffa450edef68
Takashi Sato [Sun, 20 Dec 2009 08:09:44 +0000 (08:09 +0000)]
Improve the wording.
Submitted by: OZAWA Sakuro <ozawa feedforce.jp>
Reviewed by: takashi
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@892570
13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Mon, 14 Dec 2009 15:40:50 +0000 (15:40 +0000)]
Patch from Mark Watts. Mention ProxyErrorOverride.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@890374
13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sat, 12 Dec 2009 20:27:39 +0000 (20:27 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@889972
13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Thu, 3 Dec 2009 17:24:43 +0000 (17:24 +0000)]
Default sysconfdir is conf, not etc.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@886856
13f79535 -47bb-0310-9956-
ffa450edef68
Ruediger Pluem [Sat, 21 Nov 2009 09:00:06 +0000 (09:00 +0000)]
* Remove comments and vote
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@882861
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Fri, 20 Nov 2009 15:43:31 +0000 (15:43 +0000)]
Update patch proposal, add comment.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@882610
13f79535 -47bb-0310-9956-
ffa450edef68
Ruediger Pluem [Fri, 20 Nov 2009 12:09:17 +0000 (12:09 +0000)]
* Comment and vote.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@882528
13f79535 -47bb-0310-9956-
ffa450edef68
Rainer Jung [Fri, 20 Nov 2009 10:07:22 +0000 (10:07 +0000)]
Add backport proposal for CVE-2009-3555
(r833622 from 2.2.x).
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@882479
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Sat, 17 Oct 2009 03:09:10 +0000 (03:09 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@826172
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Sat, 17 Oct 2009 03:08:38 +0000 (03:08 +0000)]
update for sync with English doc.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@826171
13f79535 -47bb-0310-9956-
ffa450edef68
André Malo [Sun, 20 Sep 2009 18:58:11 +0000 (18:58 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@817080
13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Wed, 2 Sep 2009 12:04:32 +0000 (12:04 +0000)]
Adds reference to IRC channel.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@810469
13f79535 -47bb-0310-9956-
ffa450edef68
Roy T. Fielding [Mon, 3 Aug 2009 23:59:49 +0000 (23:59 +0000)]
backport r800196
Remove some duplicate extensions (reported by Jacob Rus)
Add more unregistered Microsoft types for silverlight (idiots)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@800632
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 3 Jul 2009 08:07:58 +0000 (08:07 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@790824
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Fri, 3 Jul 2009 08:07:18 +0000 (08:07 +0000)]
update for sync with English doc.
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@790823
13f79535 -47bb-0310-9956-
ffa450edef68
Rich Bowen [Wed, 10 Jun 2009 19:43:11 +0000 (19:43 +0000)]
Remove reference to ResourceConfig, AccessConfig
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@783470
13f79535 -47bb-0310-9956-
ffa450edef68
William A. Rowe Jr [Fri, 29 May 2009 14:44:26 +0000 (14:44 +0000)]
not likely to release except security, but fix broken platform autogunk
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@780001
13f79535 -47bb-0310-9956-
ffa450edef68
Roy T. Fielding [Wed, 13 May 2009 21:58:10 +0000 (21:58 +0000)]
merge from trunk r774530
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@774551
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Tue, 14 Apr 2009 08:10:12 +0000 (08:10 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@764700
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Tue, 14 Apr 2009 08:08:18 +0000 (08:08 +0000)]
New Turkish translation
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@764699
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 16 Feb 2009 12:12:51 +0000 (12:12 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@744904
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Mon, 16 Feb 2009 12:10:24 +0000 (12:10 +0000)]
some modifications to generate the man pages in other languages
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@744903
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Thu, 12 Feb 2009 14:21:18 +0000 (14:21 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@743759
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Thu, 12 Feb 2009 14:19:55 +0000 (14:19 +0000)]
New Turkish translation
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@743758
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Wed, 4 Feb 2009 01:22:05 +0000 (01:22 +0000)]
update transformation
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@740562
13f79535 -47bb-0310-9956-
ffa450edef68
Nilgun Belma Buguner [Wed, 4 Feb 2009 00:14:42 +0000 (00:14 +0000)]
New Turkish translation
Translated by: Nilgün Belma Bugüner <nilgun belgeler.org>
Reviewed by: Orhan Berent <berent belgeler.org>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@740528
13f79535 -47bb-0310-9956-
ffa450edef68
Eric Covener [Fri, 9 Jan 2009 22:05:00 +0000 (22:05 +0000)]
backport r104924:
Fix Bug 18388 (Set-Cookie in 304)
Reviewed By: fielding, wrowe, covener
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@733168
13f79535 -47bb-0310-9956-
ffa450edef68