From 3df898331b4ecb25ac5d15bc63f309ff8c36040d Mon Sep 17 00:00:00 2001 From: Greg Ames Date: Fri, 27 Jan 2012 21:48:39 +0000 Subject: [PATCH] vote for the 2.2.x pregsub patch git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@1236900 13f79535-47bb-0310-9956-ffa450edef68 --- STATUS | 1 + 1 file changed, 1 insertion(+) diff --git a/STATUS b/STATUS index 12631fa7290..e83042ba117 100644 --- a/STATUS +++ b/STATUS @@ -137,6 +137,7 @@ RELEASE SHOWSTOPPERS: Fix integer overflow in ap_pregsub() which, when the mod_setenvif module is enabled, could allow local users to gain privileges via a .htaccess file. [Stefan Fritsch, Greg Ames] + +1: gregames (r1227280 from 2.2.x) *) SECURITY: CVE-2011-4317 (cve.mitre.org) Resolve additional cases of URL rewriting with ProxyPassMatch or -- 2.47.2