/[Apache-SVN]
ViewVC logotype

Revision 1230069


Jump to revision: Previous Next
Author: jorton
Date: Wed Jan 11 14:45:02 2012 UTC (12 years, 4 months ago)
Changed paths: 2
Log Message:
Merge r1230065 from trunk (adapted to avoid MMN change):

SECURITY (CVE-2012-0031): Fix possible crash on shutdown if a child
changes the sb_type field in the scoreboard.  Since unprivileged
children should not be able to affect the parent in this way, this is
treated as a Low severity security issue.

Thanks to "halfdog" <me halfdog.net> for reporting this issue.

* server/scoreboard.c (ap_cleanup_scoreboard, ap_create_scoreboard):
  Use a static global to store an authoritative copy of the scoreboard
  type.


Changed paths

Path Details
Directoryhttpd/httpd/branches/2.4.x/CHANGES modified , text changed
Directoryhttpd/httpd/branches/2.4.x/server/scoreboard.c modified , text changed

infrastructure at apache.org
ViewVC Help
Powered by ViewVC 1.1.26