You are viewing a plain text version of this content. The canonical link for it is here.
Posted to cvs@httpd.apache.org by wr...@apache.org on 2016/07/26 16:50:19 UTC

svn commit: r1754158 - in /httpd/httpd/branches: 2.2.x/STATUS 2.4.x/STATUS

Author: wrowe
Date: Tue Jul 26 16:50:18 2016
New Revision: 1754158

URL: http://svn.apache.org/viewvc?rev=1754158&view=rev
Log:
Propose showstopper fix for httpoxy mitigation

Modified:
    httpd/httpd/branches/2.2.x/STATUS
    httpd/httpd/branches/2.4.x/STATUS

Modified: httpd/httpd/branches/2.2.x/STATUS
URL: http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/STATUS?rev=1754158&r1=1754157&r2=1754158&view=diff
==============================================================================
--- httpd/httpd/branches/2.2.x/STATUS (original)
+++ httpd/httpd/branches/2.2.x/STATUS Tue Jul 26 16:50:18 2016
@@ -99,6 +99,12 @@ CURRENT RELEASE NOTES:
 
 RELEASE SHOWSTOPPERS:
 
+  *) core: CVE-2016-5387: Mitigate [f]cgi "httpoxy" issues
+      Trunk version of patch:
+         http://svn.apache.org/viewvc?rev=1753228&view=rev
+      Backport version for 2.4.x of patch:
+         Trunk version of patch works (modulo CHANGES)
+      +1: wrowe
 
 PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
   [ start all new proposals below, under PATCHES PROPOSED. ]

Modified: httpd/httpd/branches/2.4.x/STATUS
URL: http://svn.apache.org/viewvc/httpd/httpd/branches/2.4.x/STATUS?rev=1754158&r1=1754157&r2=1754158&view=diff
==============================================================================
--- httpd/httpd/branches/2.4.x/STATUS (original)
+++ httpd/httpd/branches/2.4.x/STATUS Tue Jul 26 16:50:18 2016
@@ -113,6 +113,13 @@ CURRENT RELEASE NOTES:
 
 RELEASE SHOWSTOPPERS:
 
+  *) core: CVE-2016-5387: Mitigate [f]cgi "httpoxy" issues
+      Trunk version of patch:
+         http://svn.apache.org/viewvc?rev=1753228&view=rev
+         http://svn.apache.org/viewvc?rev=1753229&view=rev
+      Backport version for 2.4.x of patch:
+         Trunk version of patch works (modulo CHANGES)
+      +1: wrowe
 
 PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
   [ start all new proposals below, under PATCHES PROPOSED. ]