httpd-bugs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
Subject DO NOT REPLY [Bug 48359] Buffer overflow related to setting RequestHeader
Date Tue, 15 Dec 2009 11:02:47 GMT

Jake Scott <> changed:

           What    |Removed                     |Added
                 CC|                            |jacob.scott@morganstanley.c
                   |                            |om

--- Comment #3 from Jake Scott <> 2009-12-15 03:02:45 UTC
The fix does make sense, but I think that this means that the behavior of the
Request headers is different to that of the Response headers w.r.t.

Core Apache makes a copy of the outgoing headers when calling a sub-request --
so any changes that mod_headers make are discarded at the end of the subrequest
and don't effect the rest of the processing.

Request headers are passed to a sub-request by reference, so a change by
mod_headers in a sub-request persists into the rest of the processing.

If this is by design then fine, but I think that needs to be documented.  I
tend to think that making a copy of the request headers as is done for the
response headers is more consistent.


Jake Scott

Configure bugmail:
------- You are receiving this mail because: -------
You are the assignee for the bug.

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message