httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "William A. Rowe Jr." <wr...@rowe-clan.net>
Subject Re: DO NOT REPLY [Bug 48359] Buffer overflow related to setting RequestHeader
Date Tue, 19 Jan 2010 20:27:57 GMT
https://issues.apache.org/bugzilla/show_bug.cgi?id=48359

> --- Comment #4 from Will Rowe <wrowe@apache.org> 2010-01-19 12:17:53 UTC ---
> I agree with Jake; letting the subrequest manipulate the input headers is
> probably not the way to go; I'd suggest reverting the trunk patch and applying
> his proposed solution.
> 
> Copying the input header array seems like a better patch than the solution 
> in trunk, and more consistant with user and module author expectations.

Thoughts?  I'd like to see this advance to 2.2 before we tag again, but if Trunk
needs adjustment before backporting, it seems silly to add it to STATUS.

Mime
View raw message