Change to Module DB

2012-01-19 Thread Apache Module Site
User ID : 1527 Title: mod_proxy_filter_xff Details : https://modules.apache.org/search.php?id=2571

Re: [RFC] further proxy/rewrite URL validation security issue (CVE-2011-4317)

2012-01-19 Thread Tomas Hoger
Jeff Trawick writes: scheme: @localhost, path: :8880 not a valid scheme; apr_uri_parse should have failed it for that reason (needs to start with lower case, continue with lower case or digit or +.-) ... so: does fixing apr_uri_parse() resolve these? not generally (but I opened bug

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-19 Thread Noel Butler
On Wed, 2012-01-18 at 14:12 +0200, Graham Leggett wrote: This never was a problem in 2.2, if one disabled dav it was disabled, as it should be disabled, fully, not only in parts, here and there, granted it's now changed because modules are no longer defaulted to statically built, but

Re: [PATCH] CVE-2011-3368, CVE-2011-4317, trunk

2012-01-19 Thread Joe Orton
On Wed, Jan 18, 2012 at 11:16:18AM -0500, Jeff Trawick wrote: Following the thread http://mail-archives.apache.org/mod_mbox/httpd-dev/201112.mbox/%3CCAKUrXK4uwT%3DP1KtEziNqFdxXs%2BtyWvggzpL8x2u-Bbq8tZ-Zsw%40mail.gmail.com%3E and the related discussion in 2.2.x/STATUS, attached is a patch for

Re: [PATCH] CVE-2011-3368, CVE-2011-4317, trunk

2012-01-19 Thread Jeff Trawick
On Thu, Jan 19, 2012 at 6:15 AM, Joe Orton jor...@redhat.com wrote: On Wed, Jan 18, 2012 at 11:16:18AM -0500, Jeff Trawick wrote: Following the thread http://mail-archives.apache.org/mod_mbox/httpd-dev/201112.mbox/%3CCAKUrXK4uwT%3DP1KtEziNqFdxXs%2BtyWvggzpL8x2u-Bbq8tZ-Zsw%40mail.gmail.com%3E

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-19 Thread Steffen
Runs fine on win, except the bugs you already know. No new ones reported. Be honest in the announce, whatever it is beta/RC/GA, and mention the bugs. And not hidden for (end)users somewhere in bugzilla or else. Should be very appreciated by the community. We realize that nothing is perfect,

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-19 Thread Rainer Jung
On 19.01.2012 07:14, Kaspar Brand wrote: On 19.01.2012 03:28, Rainer Jung wrote: OpenSSL should be 1.0.0f and the strange thing is, that the same tests succeed on Solaris 10 using the same OpenSSL version. Something must be different between my Linux systems, which all fail, and the Solaris

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-19 Thread Rainer Jung
On 16.01.2012 18:50, Jim Jagielski wrote: The 2.4.0 (prerelease) tarballs are available for download and test: http://httpd.apache.org/dev/dist/ I'm calling a VOTE on releasing these as Apache httpd 2.4.0 GA. Vote will last the normal 72 hours... Can I get a w00t w00t! +1 for GA. I

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-19 Thread Kaspar Brand
On 19.01.2012 14:49, Rainer Jung wrote: On 19.01.2012 07:14, Kaspar Brand wrote: On 19.01.2012 03:28, Rainer Jung wrote: Additional info: even on the failing systems, CRL checks done for other tests in the suite do succeed. Example: [Thu Jan 19 02:33:50.878506 2012] [ssl:debug] [pid 5240]