Bug#530834: CVE-2009-1195: Apache HTTP Server AllowOverride Options Security Bypass

2009-05-28 Thread Giuseppe Iuculano
Package: apache2 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, redhat recently patched apache2. CVE-2009-1195 is still reserved, but is disclosed in RHSA-2009-1075[1] A security issue has been reported in Apache HTTP Server, which can be exploited

Bug#530834: CVE-2009-1195: Apache HTTP Server AllowOverride Options Security Bypass

2009-05-28 Thread Stefan Fritsch
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1195 https://bugzilla.redhat.com/show_bug.cgi?id=489436 Patch: http://svn.apache.org/viewvc?view=revrevision=772997 If I understood the discussion on httpd-dev correctly, the fix in trunk svn breaks API compatibility and makes mod_perl