CVS log for ports/www/apache20/files/Attic/patch-secfix-ssl_engine_kernel.c
Up to [FreeBSD] / ports / www / apache20 / files
Request diff between arbitrary revisions
Keyword substitution: kv
Default branch: MAIN
Revision 1.2
Tue Jul 26 10:10:35 2005 UTC (6 years, 6 months ago) by clement
Branches: MAIN
CVS tags: HEAD
FILE REMOVED
Changes since revision 1.1: +0 -0 lines
- Add fix for CAN-2005-2088
From Changelog:
*) SECURITY: CAN-2005-2088
core: If a request contains both Transfer-Encoding and Content-Length
headers, remove the Content-Length, mitigating some HTTP Request
Splitting/Spoofing attacks. [Paul Querna, Joe Orton]
- Rename previous patch to CVE ID
- bump PORTREVISION
Security: CAN-2005-2088
Obtained From: Apache repository
Revision 1.1: download - view: text, markup, annotated - select for diffs
Tue Jul 26 08:25:13 2005 UTC (6 years, 6 months ago) by clement
Branches: MAIN
Security: fix a buffer overrun in ssl_callback_SSLVerify_CRL() Reported by: thierry
