Fwd: Re: [RFC] further proxy/rewrite URL validation security issue (CVE-2011-4317)

2012-01-17 Thread William A. Rowe Jr.
Original Message Subject: Re: [RFC] further proxy/rewrite URL validation security issue (CVE-2011-4317) Date: Tue, 17 Jan 2012 16:47:01 -0500 From: Jeff Trawick Reply-To: d...@httpd.apache.org To: d...@httpd.apache.org On Thu, Jan 12, 2012 at 4:54 AM, Tomas Hoger wrote

Re: [RFC] further proxy/rewrite URL validation security issue (CVE-2011-4317)

2012-01-10 Thread Jeff Trawick
On Fri, Dec 16, 2011 at 7:35 PM, William A. Rowe Jr. wrote: > On 12/16/2011 3:13 AM, Joe Orton wrote: >> On Thu, Dec 15, 2011 at 10:04:03AM -0500, Jeff Trawick wrote: >>> On Wed, Nov 23, 2011 at 9:23 AM, Joe Orton wrote: Prutha Parikh from Qualys reported a variant on the CVE-2011-3368 attac

Re: [RFC] further proxy/rewrite URL validation security issue (CVE-2011-4317)

2011-12-16 Thread William A. Rowe Jr.
On 12/16/2011 3:13 AM, Joe Orton wrote: > On Thu, Dec 15, 2011 at 10:04:03AM -0500, Jeff Trawick wrote: >> On Wed, Nov 23, 2011 at 9:23 AM, Joe Orton wrote: >>> Prutha Parikh from Qualys reported a variant on the CVE-2011-3368 attack >>> against certain mod_proxy/mod_rewrite configurations. A new