Re: [PATCH] CVE-2006-5752 for 1.3.x

2007-07-24 Thread Sander Temme
On Jul 24, 2007, at 6:25 AM, Jeff Trawick wrote: On 7/20/07, Jeff Trawick <[EMAIL PROTECTED]> wrote: On 7/20/07, Sander Temme <[EMAIL PROTECTED]> wrote: > > On Jul 20, 2007, at 7:30 AM, Jeff Trawick wrote: > > > Index: src/modules/standard/mod_status.c > > +1, it's the same stuff we did for 2.

Re: [PATCH] CVE-2006-5752 for 1.3.x

2007-07-24 Thread Joe Orton
On Tue, Jul 24, 2007 at 09:25:45AM -0400, Jeff Trawick wrote: > On 7/20/07, Jeff Trawick <[EMAIL PROTECTED]> wrote: > >On 7/20/07, Sander Temme <[EMAIL PROTECTED]> wrote: > >> > >> On Jul 20, 2007, at 7:30 AM, Jeff Trawick wrote: > >> > >> > Index: src/modules/standard/mod_status.c > >> > >> +1, it

Re: [PATCH] CVE-2006-5752 for 1.3.x

2007-07-24 Thread Jeff Trawick
On 7/20/07, Jeff Trawick <[EMAIL PROTECTED]> wrote: On 7/20/07, Sander Temme <[EMAIL PROTECTED]> wrote: > > On Jul 20, 2007, at 7:30 AM, Jeff Trawick wrote: > > > Index: src/modules/standard/mod_status.c > > +1, it's the same stuff we did for 2.2 in r549159. > > What about the ap_escape_logitem s

Re: [PATCH] CVE-2006-5752 for 1.3.x

2007-07-20 Thread Jeff Trawick
On 7/20/07, Sander Temme <[EMAIL PROTECTED]> wrote: On Jul 20, 2007, at 7:30 AM, Jeff Trawick wrote: > Index: src/modules/standard/mod_status.c +1, it's the same stuff we did for 2.2 in r549159. What about the ap_escape_logitem stuff in that same commit, does that apply to 1.3? it is applic

Re: [PATCH] CVE-2006-5752 for 1.3.x

2007-07-20 Thread Sander Temme
On Jul 20, 2007, at 7:30 AM, Jeff Trawick wrote: Index: src/modules/standard/mod_status.c +1, it's the same stuff we did for 2.2 in r549159. What about the ap_escape_logitem stuff in that same commit, does that apply to 1.3? S. -- Sander Temme [EMAIL PROTECTED] PGP FP: 51B4 8727 466A 0B

[PATCH] CVE-2006-5752 for 1.3.x

2007-07-20 Thread Jeff Trawick
Index: src/modules/standard/mod_status.c === --- src/modules/standard/mod_status.c (revision 558006) +++ src/modules/standard/mod_status.c (working copy) @@ -221,7 +221,7 @@ if (r->method_number != M_GET) return DECLINE