httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Plüm, Rüdiger, VF-Group" <>
Subject RE: svn commit: r791454 - in /httpd/httpd/branches/2.2.x: CHANGES STATUS server/core_filters.c
Date Mon, 06 Jul 2009 12:31:39 GMT
IMHO 39605 is fixed by the patches in 2.2.x as well.
So we should close it and add its number to the comment.


	From: Jeff Trawick  
	 Sent: Montag, 6. Juli 2009 14:08
	Subject: Re: svn commit: r791454 - in /httpd/httpd/branches/2.2.x: CHANGES STATUS server/core_filters.c
	On Mon, Jul 6, 2009 at 8:03 AM, <> wrote:

		Author: trawick
		Date: Mon Jul  6 12:03:20 2009
		New Revision: 791454
		SECURITY: CVE-2009-1891 (
		Fix a potential Denial-of-Service attack against mod_deflate or other
		modules, by forcing the server to consume CPU time in compressing a
		large file after a client disconnects.  [Joe Orton, Ruediger Pluem]

	One of the patches was for, although
that has a different symptom.  (See comment in
 39605 isn't marked complete or listed in CHANGES.  Perhaps this is because more fixes are
needed to address that problem?

View raw message