[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#858373: apache2: segfaults upon recieving bad request when using worker/event mpm and cgid errordoc



This looks like a form of CVE-2015-0253, which affected upstream apache
2.4.11, was introduced by the backport.  The fix is to ensure
r->protocol is always populated:

https://svn.apache.org/viewvc?view=revision&revision=1668879

-- 
Doran Moppert
Red Hat Product Security


Reply to: