Browse Source

apply security fix

master
parent
commit
674d60d507
  1. 16
      apache/apache.patch
  2. 2
      apache/apache.spec

16
apache/apache.patch

@ -1485,3 +1485,19 @@ Index: support/htdigest.c
}
apr_file_close(f);
Index: server/core.c
--- server/core.c
+++ server/core.c
@@ -1809,6 +1809,12 @@ AP_CORE_DECLARE_NONSTD(const char *) ap_limit_section(cmd_parms *cmd,
/* method has not been registered yet, but resorce restriction
* is always checked before method handling, so register it.
*/
+ if (cmd->pool == cmd->temp_pool) {
+ /* In .htaccess, we can't globally register new methods. */
+ return apr_psprintf(cmd->pool, "Could not register method '%s' "
+ "for %s from .htaccess configuration",
+ method, cmd->cmd->name);
+ }
methnum = ap_method_register(cmd->pool, method);
}

2
apache/apache.spec

@ -32,7 +32,7 @@ Class: BASE
Group: Web
License: ASF
Version: 2.2.32
Release: 20170615
Release: 20170918
# package options
%option with_mpm_prefork yes

Loading…
Cancel
Save