<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>185442</bug_id>
          
          <creation_ts>2007-07-15 19:21 0000</creation_ts>
          <short_desc>www-servers/lighttpd &lt; 1.4.16 Multiple issues (CVE-2007-39{46,47,48,49,50}, CVE-2007-2841)</short_desc>
          <delta_ts>2007-08-25 22:11:40 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/26130</bug_file_loc>
          <status_whiteboard>B2 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bangert@gentoo.org</cc>
    
    <cc>bernd@linx.net</cc>
    
    <cc>chainsaw@gentoo.org</cc>
    
    <cc>lars@chaotika.org</cc>
    
    <cc>mips@gentoo.org</cc>
    
    <cc>phreak@gentoo.org</cc>
    
    <cc>sgtphou@fire-eyes.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 19:21:45 0000</bug_when>
            <thetext>Attaching patches in a moment.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 19:23:12 0000</bug_when>
            <thetext>Created an attachment (id=124941)
lighttpd-1.4.x_duplicated_headers_with_folding_crash.patch

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 19:23:32 0000</bug_when>
            <thetext>Created an attachment (id=124943)
lighttpd-1.4.x_mod_access_bypass.patch

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 19:23:49 0000</bug_when>
            <thetext>Created an attachment (id=124944)
lighttpd-1.4.x_mod_fastcgi_local_dos.patch

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 19:29:55 0000</bug_when>
            <thetext>Thilo please provide an updated ebuild for prestable testing. Friendly note: Do NOT commit anything yet.

Further details (not patches) will be attached later.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-07-15 22:01:48 0000</bug_when>
            <thetext>Created an attachment (id=124966)
lighttpd-1.4.15-r1.ebuild

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-07-15 22:02:19 0000</bug_when>
            <thetext>Created an attachment (id=124968)
07_all_lighttpd-1.4.15-duplicated_headers_with_folding_crash.diff

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-07-15 22:02:54 0000</bug_when>
            <thetext>Created an attachment (id=124969)
08_all_lighttpd-1.4.15-mod_access_bypass.diff

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-07-15 22:05:50 0000</bug_when>
            <thetext>Created an attachment (id=124971)
09_all_lighttpd-1.4.15-mod_fastcgi_local_dos.diff

drop the patches into files/1.4.15/ and use the attached ebuild.
the patches have been modified in naming (as to work with epatch) and minor layout (remove header) and the NEWS section update of the duplicate headers patch has been removed (clash)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-16 19:36:09 0000</bug_when>
            <thetext>Thx Thilo for the fast response.

Arch security liaisons please test and report back on this bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-16 19:44:15 0000</bug_when>
            <thetext>*** Bug 185549 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-07-16 19:45:37 0000</bug_when>
            <thetext>compiles and runs fine on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-07-16 22:07:11 0000</bug_when>
            <thetext>Works for hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-07-17 14:19:03 0000</bug_when>
            <thetext>sparc okie dokie.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-17 17:53:46 0000</bug_when>
            <thetext>Release date is tomorrow, still need status from:

x86 ppc amd64 alpha</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-07-20 06:23:10 0000</bug_when>
            <thetext>the next 10 days i&apos;ll be on vacation and thus not able to commit this babe...  sorry.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2007-07-20 13:13:50 0000</bug_when>
            <thetext>public now. somebody please commit this.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-07-20 13:25:48 0000</bug_when>
            <thetext>*** Bug 185978 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>phreak@gentoo.org</who>
            <bug_when>2007-07-20 13:41:30 0000</bug_when>
            <thetext>(In reply to comment #14)
&gt; Release date is tomorrow, still need status from:
&gt; 
&gt; x86 ppc amd64 alpha

Works for me on x86 and amd64 (passes collision-protect and works like before),
though I&apos;m no arch team person.

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-07-20 13:43:05 0000</bug_when>
            <thetext>I just wanted to commit, but wasn&apos;t sure how to do so. If we drop the patches
in ${FILESDIR}/1.4.15, then 1.4.15-r1 will be the exact same ebuild as 1.4.15
and everybody who compiles 1.4.15 will get the patches from this bug, too.

( Due to this line in the ebuild:
EPATCH_SUFFIX=&quot;diff&quot; EPATCH_OPTS=&quot;-l&quot; epatch ${FILESDIR}/${PV} || die &quot;Patching
failed!&quot; )

I could create ${FILESDIR}/1.4.15-r1, but then we have to copy over the files
from ${FILESDIR}/1.4.15, which means duplicated patches in CVS. I would do the
copy, but as this is not my package I would like to hear a comment before I
commit.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-07-20 13:56:45 0000</bug_when>
            <thetext>There&apos;s another bug as pointed by smithj, it&apos;s RPL-1554 (https://issues.rpath.com/browse/RPL-1554 and http://lists.rpath.com/pipermail/distro-commits/2007-July/055669.html).
It&apos;s patched in 1.4.15-r1 in the tree so arches will have to stable themselves because of this addition.
Corsair: switch to PVR, duplicate it for now (with 1.4.15-r1 having the sec patches) and when arches are done do a simple cleanup.
Security: arches should be called in now.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-07-20 18:16:23 0000</bug_when>
            <thetext>gustavoz: thanks for commiting, real life catched me for some hours..

ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-07-20 19:36:35 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-07-20 21:08:13 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-07-21 17:22:42 0000</bug_when>
            <thetext>make[3]: Entering directory `/var/tmp/portage/www-servers/lighttpd-1.4.15-r1/work/lighttpd-1.4.15/tests&apos;
cp: cannot stat `./docroot/www/*.html~&apos;: No such file or directory
preparing infrastructure                PASS: prepare.sh
./core-var-include....ok
./core-condition......ok
./core-request........ok
./core-response.......ok
./core-keepalive......ok
./core................ok
./mod-access..........# status failed: expected &apos;403&apos;, got &apos;404&apos;

#   Failed test &apos;\#1230 - forbid access to ...~ - trailing slash&apos;
#   at ./mod-access.t line 31.
# Looks like you failed 1 test of 4.
dubious
        Test returned status 1 (wstat 256, 0x100)
DIED. FAILED test 3
        Failed 1/4 tests, 75.00% okay
./mod-auth............ok
./mod-cgi.............ok
./mod-compress........ok
./mod-fastcgi.........# header vary is duplicated: Accept-Encoding and Accept-Encoding
ok
        34/47 skipped: various reasons
./mod-redirect........ok
./mod-userdir.........ok
./mod-rewrite.........ok
        5/5 skipped: various reasons
./request.............ok
./mod-ssi.............ok
./mod-setenv..........ok
./lowercase...........ok
./cachable............ok
Failed Test    Stat Wstat Total Fail  List of Failed
-------------------------------------------------------------------------------
./mod-access.t    1   256     4    1  3
39 subtests skipped.
Failed 1/19 test scripts. 1/278 subtests failed.
Files=19, Tests=278, 10 wallclock secs ( 2.33 cusr +  0.42 csys =  2.75 CPU)
Failed 1/19 test programs. 1/278 subtests failed.
FAIL: run-tests.pl
cleaning up                             PASS: cleanup.sh
================================
1 of 3 tests failed
Please report to jan@kneschke.de
================================
make[3]: *** [check-TESTS] Error 1
make[3]: Leaving directory `/var/tmp/portage/www-servers/lighttpd-1.4.15-r1/work/lighttpd-1.4.15/tests&apos;
make[2]: *** [check-am] Error 2
make[2]: Leaving directory `/var/tmp/portage/www-servers/lighttpd-1.4.15-r1/work/lighttpd-1.4.15/tests&apos;
make[1]: *** [check-recursive] Error 1
make[1]: Leaving directory `/var/tmp/portage/www-servers/lighttpd-1.4.15-r1/work/lighttpd-1.4.15/tests&apos;
make: *** [check-recursive] Error 1

Should we ignore them? actual stable version works fine</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-07-25 07:01:04 0000</bug_when>
            <thetext>x86 stable, the test failure is caused by the mod_access patch, but seems to be no loss in functionality....so I say: Go.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-07-25 13:53:14 0000</bug_when>
            <thetext>alpha/ia64 stable

Removing liaisons and adding remaining arches</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-07-27 20:59:55 0000</bug_when>
            <thetext>Same test failure on ppc, ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-07-30 09:58:25 0000</bug_when>
            <thetext>adding refs.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>angelos@gentoo.org</who>
            <bug_when>2007-07-31 19:37:22 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-08-05 10:51:21 0000</bug_when>
            <thetext>1.4.16 has been released - are we interested in moving to that for easier maintenance or sticking with our patchset?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-08-05 13:09:55 0000</bug_when>
            <thetext>well - someone will surely ask for it, so I put it in. I don&apos;t know where the scgi patch comes from, and it looks like it hasn&apos;t been applied upstream, so i left it out... for now.

security: can you advice? the subject mentions five CVEs, there is only three patches on this bug, while the release announcement by lighttpd lists four (and no CVEs).

Anyway, it appears that the three patches on this bug are covered by the 1.4.16 release. So, ARM: Please mark 1.4.16 stable instead of 1.4.15-r1. Thanks.

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-08-09 09:51:46 0000</bug_when>
            <thetext>Thilo: according to http://www.lighttpd.net/download, the patch about mod_auth covers 4 issues, and secunia added one more CVE ref...
wrt to the current situation, I&apos;d tend to say that it would be much simpler to stabilize 1.4.16 instead of trying to figure out this patching mess.
I&apos;m sorry for putting more work on arches teams, but I think that&apos;s the best way to go from here.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bangert@gentoo.org</who>
            <bug_when>2007-08-09 17:44:04 0000</bug_when>
            <thetext>arch teams: please mark stable: lighttpd-1.4.16</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-08-09 18:16:21 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-08-10 06:40:23 0000</bug_when>
            <thetext>x86 stable, changing status to &quot;stable&quot; again.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-08-10 13:42:38 0000</bug_when>
            <thetext>alpha/ia64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-08-10 17:46:43 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-08-12 14:48:10 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-08-14 18:04:56 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-08-14 23:01:47 0000</bug_when>
            <thetext>hppa, does something cause any trouble?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-08-15 01:56:43 0000</bug_when>
            <thetext>(In reply to comment #40)
&gt; hppa, does something cause any trouble?

No, we&apos;re just temporarily understaffed.

Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-08-15 05:43:50 0000</bug_when>
            <thetext>Rerating and setting status to glsa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-08-16 22:05:56 0000</bug_when>
            <thetext>GLSA 200708-11, thanks everybody (in time, at last ;) )</thetext>
          </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>124941</attachid>
            <date>2007-07-15 19:23 0000</date>
            <desc>lighttpd-1.4.x_duplicated_headers_with_folding_crash.patch</desc>
            <filename>lighttpd-1.4.x_duplicated_headers_with_folding_crash.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tCnIxODY5IHwgamFuIHwgMjAwNy0wNi0xNSAxNjowODozMiArMDIwMCAo
RnJpLCAxNSBKdW4gMjAwNykgfCAyIGxpbmVzCkNoYW5nZWQgcGF0aHM6CiAgIE0gL2JyYW5jaGVz
L2xpZ2h0dHBkLTEuNC54L3NyYy9yZXF1ZXN0LmMKICAgTSAvYnJhbmNoZXMvbGlnaHR0cGQtMS40
LngvdGVzdHMvY29yZS1yZXF1ZXN0LnQKCmZpeGVkIHJlbW90ZSBjcmFzaCBvbiBkdXBsaWNhdGUg
aGVhZGVyIGtleXMgd2l0aCBsaW5lLXdyYXBwaW5nIChmaXhlcyAjMTIzMCkKCi0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLQpJbmRleDogc3JjL3JlcXVlc3QuYwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBzcmMvcmVxdWVzdC5jCShy
ZXZpc2lvbiAxODY4KQorKysgc3JjL3JlcXVlc3QuYwkocmV2aXNpb24gMTg3MCkKQEAgLTI4NCw4
ICsyODQsNiBAQAogCiAJaW50IGRvbmUgPSAwOwogCi0JZGF0YV9zdHJpbmcgKmRzID0gTlVMTDsK
LQogCS8qCiAJICogUmVxdWVzdDogIl4oR0VUfFBPU1R8SEVBRCkgKFteIF0rKFxcP1teIF0rfCkp
IChIVFRQLzFcXC5bMDFdKSQiCiAJICogT3B0aW9uIDogIl4oWy1hLXpBLVpdKyk6ICguKykkIgpA
QCAtNzE1LDEyICs3MTMsMjQgQEAKIAkJCXN3aXRjaCgqY3VyKSB7CiAJCQljYXNlICdccic6CiAJ
CQkJaWYgKGNvbi0+cGFyc2VfcmVxdWVzdC0+cHRyW2krMV0gPT0gJ1xuJykgeworCQkJCQlkYXRh
X3N0cmluZyAqZHMgPSBOVUxMOworCiAJCQkJCS8qIEVuZCBvZiBIZWFkZXJsaW5lICovCiAJCQkJ
CWNvbi0+cGFyc2VfcmVxdWVzdC0+cHRyW2ldID0gJ1wwJzsKIAkJCQkJY29uLT5wYXJzZV9yZXF1
ZXN0LT5wdHJbaSsxXSA9ICdcMCc7CiAKIAkJCQkJaWYgKGluX2ZvbGRpbmcpIHsKLQkJCQkJCWlm
ICghZHMpIHsKKwkJCQkJCWJ1ZmZlciAqa2V5X2I7CisJCQkJCQkvKioKKwkJCQkJCSAqIHdlIHVz
ZSBhIGV2aWwgaGFjayB0byBoYW5kbGUgdGhlIGxpbmUtZm9sZGluZworCQkJCQkJICogCisJCQkJ
CQkgKiBBcyBhcnJheV9pbnNlcnRfdW5pcXVlKCkgZGVsZXRlcyAnZHMnIGluIHRoZSBjYXNlIG9m
IGEgZHVwbGljYXRlCisJCQkJCQkgKiBkcyBwb2ludHMgc29tZXdoZXJlIGFuZCB3ZSBnZXQgYSBl
dmlsIGNyYXNoLiBBcyBhIHNvbHV0aW9uIHdlIGtlZXAgdGhlIG9sZAorCQkJCQkJICogImtleSIg
YW5kIGdldCB0aGUgY3VycmVudCB2YWx1ZSBmcm9tIHRoZSBoYXNoIGFuZCBhcHBlbmQgdXMKKwkJ
CQkJCSAqCisJCQkJCQkgKiAqLworCisJCQkJCQlpZiAoIWtleSB8fCAha2V5X2xlbikgewogCQkJ
CQkJCS8qIDQwMCAqLwogCiAJCQkJCQkJaWYgKHNydi0+c3J2Y29uZi5sb2dfcmVxdWVzdF9oZWFk
ZXJfb25fZXJyb3IpIHsKQEAgLTczNyw3ICs3NDcsMTUgQEAKIAkJCQkJCQljb24tPnJlc3BvbnNl
LmtlZXBfYWxpdmUgPSAwOwogCQkJCQkJCXJldHVybiAwOwogCQkJCQkJfQotCQkJCQkJYnVmZmVy
X2FwcGVuZF9zdHJpbmcoZHMtPnZhbHVlLCB2YWx1ZSk7CisKKwkJCQkJCWtleV9iID0gYnVmZmVy
X2luaXQoKTsKKwkJCQkJCWJ1ZmZlcl9jb3B5X3N0cmluZ19sZW4oa2V5X2IsIGtleSwga2V5X2xl
bik7CisKKwkJCQkJCWlmIChOVUxMICE9IChkcyA9IChkYXRhX3N0cmluZyAqKWFycmF5X2dldF9l
bGVtZW50KGNvbi0+cmVxdWVzdC5oZWFkZXJzLCBrZXlfYi0+cHRyKSkpIHsKKwkJCQkJCQlidWZm
ZXJfYXBwZW5kX3N0cmluZyhkcy0+dmFsdWUsIHZhbHVlKTsKKwkJCQkJCX0KKworCQkJCQkJYnVm
ZmVyX2ZyZWUoa2V5X2IpOwogCQkJCQl9IGVsc2UgewogCQkJCQkJaW50IHNfbGVuOwogCQkJCQkJ
a2V5ID0gY29uLT5wYXJzZV9yZXF1ZXN0LT5wdHIgKyBmaXJzdDsKQEAgLTk2OSw3ICs5ODcsMTIg
QEAKIAkJCQkJZmlyc3QgPSBpKzE7CiAJCQkJCWlzX2tleSA9IDE7CiAJCQkJCXZhbHVlID0gMDsK
LQkJCQkJa2V5X2xlbiA9IDA7CisjaWYgMAorCQkJCQkvKioKKwkJCQkJICogZm9yIEJ1ZyAxMjMw
IGtlZXAgdGhlIGtleV9sZW4gYSBsaXZlCisJCQkJCSAqLworCQkJCQlrZXlfbGVuID0gMDsgCisj
ZW5kaWYKIAkJCQkJaW5fZm9sZGluZyA9IDA7CiAJCQkJfSBlbHNlIHsKIAkJCQkJaWYgKHNydi0+
c3J2Y29uZi5sb2dfcmVxdWVzdF9oZWFkZXJfb25fZXJyb3IpIHsKSW5kZXg6IHRlc3RzL2NvcmUt
cmVxdWVzdC50Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT0KLS0tIHRlc3RzL2NvcmUtcmVxdWVzdC50CShyZXZpc2lvbiAx
ODY4KQorKysgdGVzdHMvY29yZS1yZXF1ZXN0LnQJKHJldmlzaW9uIDE4NzApCkBAIC04LDcgKzgs
NyBAQAogCiB1c2Ugc3RyaWN0OwogdXNlIElPOjpTb2NrZXQ7Ci11c2UgVGVzdDo6TW9yZSB0ZXN0
cyA9PiAzMzsKK3VzZSBUZXN0OjpNb3JlIHRlc3RzID0+IDM2OwogdXNlIExpZ2h0eVRlc3Q7CiAK
IG15ICR0ZiA9IExpZ2h0eVRlc3QtPm5ldygpOwpAQCAtMjczLDYgKzI3MywzOCBAQAogJHQtPntS
RVNQT05TRX0gPSBbIHsgJ0hUVFAtUHJvdG9jb2wnID0+ICdIVFRQLzEuMCcsICdIVFRQLVN0YXR1
cycgPT4gMjAwIH0gXTsKIG9rKCR0Zi0+aGFuZGxlX2h0dHAoJHQpID09IDAsICd1cHBlcmNhc2Ug
ZmlsZW5hbWVzJyk7CiAKKyR0LT57UkVRVUVTVH0gID0gKCA8PEVPRgorR0VUIC8gSFRUUC8xLjAK
K0xvY2F0aW9uOiBmb28KK0xvY2F0aW9uOiBmb29iYXIKKyAgYmF6CitFT0YKKyApOworJHQtPntS
RVNQT05TRX0gPSBbIHsgJ0hUVFAtUHJvdG9jb2wnID0+ICdIVFRQLzEuMCcsICdIVFRQLVN0YXR1
cycgPT4gMjAwIH0gXTsKK29rKCR0Zi0+aGFuZGxlX2h0dHAoJHQpID09IDAsICcjMTIzMiAtIGR1
cGxpY2F0ZSBoZWFkZXJzIHdpdGggbGluZS13cmFwcGluZycpOwogCiskdC0+e1JFUVVFU1R9ICA9
ICggPDxFT0YKK0dFVCAvIEhUVFAvMS4wCitMb2NhdGlvbjogCitMb2NhdGlvbjogZm9vYmFyCisg
IGJhegorRU9GCisgKTsKKyR0LT57UkVTUE9OU0V9ID0gWyB7ICdIVFRQLVByb3RvY29sJyA9PiAn
SFRUUC8xLjAnLCAnSFRUUC1TdGF0dXMnID0+IDIwMCB9IF07CitvaygkdGYtPmhhbmRsZV9odHRw
KCR0KSA9PSAwLCAnIzEyMzIgLSBkdXBsaWNhdGUgaGVhZGVycyB3aXRoIGxpbmUtd3JhcHBpbmcg
LSB0ZXN0IDInKTsKKworJHQtPntSRVFVRVNUfSAgPSAoIDw8RU9GCitHRVQgLyBIVFRQLzEuMAor
QTogCitMb2NhdGlvbjogZm9vYmFyCisgIGJhegorRU9GCisgKTsKKyR0LT57UkVTUE9OU0V9ID0g
WyB7ICdIVFRQLVByb3RvY29sJyA9PiAnSFRUUC8xLjAnLCAnSFRUUC1TdGF0dXMnID0+IDIwMCB9
IF07CitvaygkdGYtPmhhbmRsZV9odHRwKCR0KSA9PSAwLCAnIzEyMzIgLSBkdXBsaWNhdGUgaGVh
ZGVycyB3aXRoIGxpbmUtd3JhcHBpbmcgLSB0ZXN0IDMnKTsKKworCisKKwogb2soJHRmLT5zdG9w
X3Byb2MgPT0gMCwgIlN0b3BwaW5nIGxpZ2h0dHBkIik7CiAK
</data>        

          </attachment>
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>124943</attachid>
            <date>2007-07-15 19:23 0000</date>
            <desc>lighttpd-1.4.x_mod_access_bypass.patch</desc>
            <filename>lighttpd-1.4.x_mod_access_bypass.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tCnIxODcxIHwgamFuIHwgMjAwNy0wNi0xNSAxNjo0NjoxNyArMDIwMCAo
RnJpLCAxNSBKdW4gMjAwNykgfCAyIGxpbmVzCkNoYW5nZWQgcGF0aHM6CiAgIE0gL2JyYW5jaGVz
L2xpZ2h0dHBkLTEuNC54L3NyYy9tb2RfYWNjZXNzLmMKICAgTSAvYnJhbmNoZXMvbGlnaHR0cGQt
MS40LngvdGVzdHMvZG9jcm9vdC93d3cvTWFrZWZpbGUuYW0KICAgQSAvYnJhbmNoZXMvbGlnaHR0
cGQtMS40LngvdGVzdHMvZG9jcm9vdC93d3cvaW5kZXguaHRtbH4KICAgTSAvYnJhbmNoZXMvbGln
aHR0cGQtMS40LngvdGVzdHMvbW9kLWFjY2Vzcy50CiAgIE0gL2JyYW5jaGVzL2xpZ2h0dHBkLTEu
NC54L3Rlc3RzL3ByZXBhcmUuc2gKCmNoZWNrIHRoZSBVUkwgdHdpY2UsIGJlZm9yZSBhbmQgYWZ0
ZXIgcGF0aC1pbmZvIGhhbmRsaW5nLiAoZml4ZXMgIzEyMzApCgotLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0KSW5k
ZXg6IHNyYy9tb2RfYWNjZXNzLmMKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gc3JjL21vZF9hY2Nlc3MuYwkocmV2
aXNpb24gMTg3MCkKKysrIHNyYy9tb2RfYWNjZXNzLmMJKHJldmlzaW9uIDE4NzEpCkBAIC0xMTEs
NiArMTExLDE1IEBACiB9CiAjdW5kZWYgUEFUQ0gKIAorLyoqCisgKiBVUkkgaGFuZGxlcgorICoK
KyAqIHdlIHdpbGwgZ2V0IGNhbGxlZCB0d2ljZToKKyAqIC0gYWZ0ZXIgdGhlIGNsZWFuIHVwIG9m
IHRoZSBVUkwgYW5kIAorICogLSBhZnRlciB0aGUgcGF0aGluZm8gY2hlY2tzIGFyZSBkb25lCisg
KgorICogdGhpcyBoYW5kbGVzIHRoZSBpc3N1ZSBvZiB0cmFpbGluZyBzbGFzaGVzCisgKi8KIFVS
SUhBTkRMRVJfRlVOQyhtb2RfYWNjZXNzX3VyaV9oYW5kbGVyKSB7CiAJcGx1Z2luX2RhdGEgKnAg
PSBwX2Q7CiAJaW50IHNfbGVuOwpAQCAtMTIyLDI4ICsxMzEsNDEgQEAKIAogCXNfbGVuID0gY29u
LT51cmkucGF0aC0+dXNlZCAtIDE7CiAKKwlpZiAoY29uLT5jb25mLmxvZ19yZXF1ZXN0X2hhbmRs
aW5nKSB7CisgCQlsb2dfZXJyb3Jfd3JpdGUoc3J2LCBfX0ZJTEVfXywgX19MSU5FX18sICJzIiwg
CisJCQkJIi0tIG1vZF9hY2Nlc3NfdXJpX2hhbmRsZXIgY2FsbGVkIik7CisJfQorCiAJZm9yIChr
ID0gMDsgayA8IHAtPmNvbmYuYWNjZXNzX2RlbnktPnVzZWQ7IGsrKykgewogCQlkYXRhX3N0cmlu
ZyAqZHMgPSAoZGF0YV9zdHJpbmcgKilwLT5jb25mLmFjY2Vzc19kZW55LT5kYXRhW2tdOwogCQlp
bnQgY3RfbGVuID0gZHMtPnZhbHVlLT51c2VkIC0gMTsKKwkJaW50IGRlbmllZCA9IDA7CiAKKwog
CQlpZiAoY3RfbGVuID4gc19sZW4pIGNvbnRpbnVlOwotCiAJCWlmIChkcy0+dmFsdWUtPnVzZWQg
PT0gMCkgY29udGludWU7CiAKIAkJLyogaWYgd2UgaGF2ZSBhIGNhc2UtaW5zZW5zaXRpdmUgRlMg
d2UgaGF2ZSB0byBsb3dlci1jYXNlIHRoZSBVUkkgaGVyZSB0b28gKi8KIAogCQlpZiAoY29uLT5j
b25mLmZvcmNlX2xvd2VyY2FzZV9maWxlbmFtZXMpIHsKIAkJCWlmICgwID09IHN0cm5jYXNlY21w
KGNvbi0+dXJpLnBhdGgtPnB0ciArIHNfbGVuIC0gY3RfbGVuLCBkcy0+dmFsdWUtPnB0ciwgY3Rf
bGVuKSkgewotCQkJCWNvbi0+aHR0cF9zdGF0dXMgPSA0MDM7Ci0KLQkJCQlyZXR1cm4gSEFORExF
Ul9GSU5JU0hFRDsKKwkJCQlkZW5pZWQgPSAxOwogCQkJfQogCQl9IGVsc2UgewogCQkJaWYgKDAg
PT0gc3RybmNtcChjb24tPnVyaS5wYXRoLT5wdHIgKyBzX2xlbiAtIGN0X2xlbiwgZHMtPnZhbHVl
LT5wdHIsIGN0X2xlbikpIHsKLQkJCQljb24tPmh0dHBfc3RhdHVzID0gNDAzOworCQkJCWRlbmll
ZCA9IDE7CisJCQl9CisJCX0KIAotCQkJCXJldHVybiBIQU5ETEVSX0ZJTklTSEVEOworCQlpZiAo
ZGVuaWVkKSB7CisJCQljb24tPmh0dHBfc3RhdHVzID0gNDAzOworCisJCQlpZiAoY29uLT5jb25m
LmxvZ19yZXF1ZXN0X2hhbmRsaW5nKSB7CisJIAkJCWxvZ19lcnJvcl93cml0ZShzcnYsIF9fRklM
RV9fLCBfX0xJTkVfXywgInNiIiwgCisJCQkJCSJ1cmwgZGVuaWVkIGFzIHdlIG1hdGNoOiIsIGRz
LT52YWx1ZSk7CiAJCQl9CisKKwkJCXJldHVybiBIQU5ETEVSX0ZJTklTSEVEOwogCQl9CiAJfQog
CkBAIC0xNTgsNyArMTgwLDggQEAKIAogCXAtPmluaXQgICAgICAgID0gbW9kX2FjY2Vzc19pbml0
OwogCXAtPnNldF9kZWZhdWx0cyA9IG1vZF9hY2Nlc3Nfc2V0X2RlZmF1bHRzOwotCXAtPmhhbmRs
ZV91cmlfY2xlYW4gID0gbW9kX2FjY2Vzc191cmlfaGFuZGxlcjsKKwlwLT5oYW5kbGVfdXJpX2Ns
ZWFuID0gbW9kX2FjY2Vzc191cmlfaGFuZGxlcjsKKwlwLT5oYW5kbGVfc3VicmVxdWVzdF9zdGFy
dCAgPSBtb2RfYWNjZXNzX3VyaV9oYW5kbGVyOwogCXAtPmNsZWFudXAgICAgID0gbW9kX2FjY2Vz
c19mcmVlOwogCiAJcC0+ZGF0YSAgICAgICAgPSBOVUxMOwpJbmRleDogdGVzdHMvbW9kLWFjY2Vz
cy50Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT0KLS0tIHRlc3RzL21vZC1hY2Nlc3MudAkocmV2aXNpb24gMTg3MCkKKysr
IHRlc3RzL21vZC1hY2Nlc3MudAkocmV2aXNpb24gMTg3MSkKQEAgLTgsNyArOCw3IEBACiAKIHVz
ZSBzdHJpY3Q7CiB1c2UgSU86OlNvY2tldDsKLXVzZSBUZXN0OjpNb3JlIHRlc3RzID0+IDM7Cit1
c2UgVGVzdDo6TW9yZSB0ZXN0cyA9PiA0OwogdXNlIExpZ2h0eVRlc3Q7CiAKIG15ICR0ZiA9IExp
Z2h0eVRlc3QtPm5ldygpOwpAQCAtMjMsNSArMjMsMTIgQEAKICR0LT57UkVTUE9OU0V9ID0gWyB7
ICdIVFRQLVByb3RvY29sJyA9PiAnSFRUUC8xLjAnLCAnSFRUUC1TdGF0dXMnID0+IDQwMyB9IF07
CiBvaygkdGYtPmhhbmRsZV9odHRwKCR0KSA9PSAwLCAnZm9yYmlkIGFjY2VzcyB0byAuLi5+Jyk7
CiAKKyR0LT57UkVRVUVTVH0gID0gKCA8PEVPRgorR0VUIC9pbmRleC5odG1sfi8gSFRUUC8xLjAK
K0VPRgorICk7CiskdC0+e1JFU1BPTlNFfSA9IFsgeyAnSFRUUC1Qcm90b2NvbCcgPT4gJ0hUVFAv
MS4wJywgJ0hUVFAtU3RhdHVzJyA9PiA0MDMgfSBdOworb2soJHRmLT5oYW5kbGVfaHR0cCgkdCkg
PT0gMCwgJyMxMjMwIC0gZm9yYmlkIGFjY2VzcyB0byAuLi5+IC0gdHJhaWxpbmcgc2xhc2gnKTsK
Kwogb2soJHRmLT5zdG9wX3Byb2MgPT0gMCwgIlN0b3BwaW5nIGxpZ2h0dHBkIik7CiAKSW5kZXg6
IHRlc3RzL3ByZXBhcmUuc2gKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gdGVzdHMvcHJlcGFyZS5zaAkocmV2aXNp
b24gMTg3MCkKKysrIHRlc3RzL3ByZXBhcmUuc2gJKHJldmlzaW9uIDE4NzEpCkBAIC0yNSw2ICsy
NSw3IEBACiAjIGNvcHkgZXZlcnl0aGluZyBpbnRvIHRoZSByaWdodCBwbGFjZXMKIGNwICRzcmNk
aXIvZG9jcm9vdC93d3cvKi5odG1sIFwKICAgICRzcmNkaXIvZG9jcm9vdC93d3cvKi5waHAgXAor
ICAgJHNyY2Rpci9kb2Nyb290L3d3dy8qLmh0bWx+IFwKICAgICRzcmNkaXIvZG9jcm9vdC93d3cv
Ki5wbCBcCiAgICAkc3JjZGlyL2RvY3Jvb3Qvd3d3LyouZmNnaSBcCiAgICAkc3JjZGlyL2RvY3Jv
b3Qvd3d3Lyouc2h0bWwgXApJbmRleDogdGVzdHMvZG9jcm9vdC93d3cvaW5kZXguaHRtbH4KPT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PQpJbmRleDogdGVzdHMvZG9jcm9vdC93d3cvTWFrZWZpbGUuYW0KPT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQot
LS0gdGVzdHMvZG9jcm9vdC93d3cvTWFrZWZpbGUuYW0JKHJldmlzaW9uIDE4NzApCisrKyB0ZXN0
cy9kb2Nyb290L3d3dy9NYWtlZmlsZS5hbQkocmV2aXNpb24gMTg3MSkKQEAgLTEsNSArMSw1IEBA
CiBFWFRSQV9ESVNUPWNnaS5waHAgY2dpLnBsIGR1bW15ZGlyIGluZGV4Lmh0bWwgaW5kZXgudHh0
IHBocGluZm8ucGhwIFwKIAkgICByZWRpcmVjdC5waHAgY2dpLXBhdGhpbmZvLnBsIGdldC1lbnYu
cGhwIGdldC1zZXJ2ZXItZW52LnBocCBcCiAJICAgbnBoLXN0YXR1cy5wbCBwcmVmaXguZmNnaSBn
ZXQtaGVhZGVyLnBsIHNzaS5zaHRtbCBnZXQtcG9zdC1sZW4ucGwgXAotCSAgIGV4ZWMtZGF0ZS5z
aHRtbAorCSAgIGV4ZWMtZGF0ZS5zaHRtbCBpbmRleC5odG1sfgogU1VCRElSUz1nbyBpbmRleGZp
bGUgZXhwaXJlCg==
</data>        

          </attachment>
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>124944</attachid>
            <date>2007-07-15 19:23 0000</date>
            <desc>lighttpd-1.4.x_mod_fastcgi_local_dos.patch</desc>
            <filename>lighttpd-1.4.x_mod_fastcgi_local_dos.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IHNyYy9tb2RfZmFzdGNnaS5jCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIHNyYy9tb2RfZmFzdGNnaS5j
CShyZXZpc2lvbiAxODc4KQorKysgc3JjL21vZF9mYXN0Y2dpLmMJKHJldmlzaW9uIDE4NzkpCkBA
IC0yNDQwLDcgKzI0NDAsNiBAQAogCQliLT51c2VkID0gciArIDE7IC8qIG9uZSBleHRyYSBmb3Ig
dGhlIGZha2UgXDAgKi8KIAkJYi0+cHRyW2ItPnVzZWQgLSAxXSA9ICdcMCc7CiAJfSBlbHNlIHsK
LQkJaWYgKGVycm5vID09IEVBR0FJTikgcmV0dXJuIDA7CiAJCWxvZ19lcnJvcl93cml0ZShzcnYs
IF9fRklMRV9fLCBfX0xJTkVfXywgInNzZHNiIiwKIAkJCQkidW5leHBlY3RlZCBlbmQtb2YtZmls
ZSAocGVyaGFwcyB0aGUgZmFzdGNnaSBwcm9jZXNzIGRpZWQpOiIsCiAJCQkJInBpZDoiLCBwcm9j
LT5waWQsCkluZGV4OiBORVdTCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIE5FV1MJKHJldmlzaW9uIDE4NzgpCisr
KyBORVdTCShyZXZpc2lvbiAxODc5KQpAQCAtMTksNiArMTksOCBAQAogICAgIChyZXBvcnRlZCBi
eSBTdGVmYW4gRXNzZXIpCiAgICogZml4ZWQgcG9zc2libGUgY3Jhc2ggaW4gQXV0aC1EaWdlc3Qg
aGVhZGVyIHBhcnNlciBvbiB0cmFpbGluZyBXUyBpbiAKICAgICBtb2RfYXV0aCAocmVwb3J0ZWQg
YnkgU3RlZmFuIEVzc2VyKSAKKyAgKiBmaXhlZCBjaGVjayBvbiBzdGFsZSBlcnJubyB2YWx1ZXMs
IHdoaWNoIGJyb2tlIGhhbmRsaW5nIG9mIGJyb2tlbiBmYXN0Y2dpCisgICAgYXBwbGljYXRpb25z
LiAoIzEyNDUpCiAKIC0gMS40LjE1IC0gMjAwNy0wNC0xMwogCg==
</data>        

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>124966</attachid>
            <date>2007-07-15 22:01 0000</date>
            <desc>lighttpd-1.4.15-r1.ebuild</desc>
            <filename>lighttpd-1.4.15-r1.ebuild</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDA3IEdlbnRvbyBGb3VuZGF0aW9uCiMgRGlzdHJpYnV0ZWQgdW5k
ZXIgdGhlIHRlcm1zIG9mIHRoZSBHTlUgR2VuZXJhbCBQdWJsaWMgTGljZW5zZSB2MgojICRIZWFk
ZXI6IC92YXIvY3Zzcm9vdC9nZW50b28teDg2L3d3dy1zZXJ2ZXJzL2xpZ2h0dHBkL2xpZ2h0dHBk
LTEuNC4xNS5lYnVpbGQsdiAxLjEyIDIwMDcvMDYvMjQgMjM6NTU6NTcgdmFwaWVyIEV4cCAkCgpX
QU5UX0FVVE9DT05GPWxhdGVzdApXQU5UX0FVVE9NQUtFPWxhdGVzdAppbmhlcml0IGV1dGlscyBh
dXRvdG9vbHMgZGVwZW5kLnBocAoKREVTQ1JJUFRJT049IkxpZ2h0d2VpZ2h0IGhpZ2gtcGVyZm9y
bWFuY2Ugd2ViIHNlcnZlciIKSE9NRVBBR0U9Imh0dHA6Ly93d3cubGlnaHR0cGQubmV0LyIKU1JD
X1VSST0iaHR0cDovL3d3dy5saWdodHRwZC5uZXQvZG93bmxvYWQvJHtQfS50YXIuYnoyIgoKTElD
RU5TRT0iQlNEIgpTTE9UPSIwIgpLRVlXT1JEUz0ifmFscGhhIH5hbWQ2NCB+YXJtIH5ocHBhIH5p
YTY0IH5taXBzIH5wcGMgfnBwYzY0IH5zaCB+c3BhcmMgfnNwYXJjLWZic2Qgfng4NiB+eDg2LWZi
c2QiCklVU0U9ImJ6aXAyIGRvYyBmYW0gZmFzdGNnaSBnZGJtIGlwdjYgbGRhcCBsdWEgbWluaW1h
bCBtZW1jYWNoZSBteXNxbCBwY3JlIHBocCBycmR0b29sIHNzbCB0ZXN0IHdlYmRhdiB4YXR0ciIK
ClJERVBFTkQ9Ij49c3lzLWxpYnMvemxpYi0xLjEKCWJ6aXAyPyAgICAoIGFwcC1hcmNoL2J6aXAy
ICkKCWZhbT8gICAgICAoIHZpcnR1YWwvZmFtICkKCWdkYm0/ICAgICAoIHN5cy1saWJzL2dkYm0g
KQoJbGRhcD8gICAgICggPj1uZXQtbmRzL29wZW5sZGFwLTIuMS4yNiApCglsdWE/ICAgICAgKCA+
PWRldi1sYW5nL2x1YS01LjEgKQoJbWVtY2FjaGU/ICggZGV2LWxpYnMvbGlibWVtY2FjaGUgKQoJ
bXlzcWw/ICAgICggPj12aXJ0dWFsL215c3FsLTQuMCApCglwY3JlPyAgICAgKCA+PWRldi1saWJz
L2xpYnBjcmUtMy4xICkKCXBocD8gICAgICAoIHZpcnR1YWwvaHR0cGQtcGhwICkKCXJyZHRvb2w/
ICggbmV0LWFuYWx5emVyL3JyZHRvb2wgKQoJc3NsPyAgICAoID49ZGV2LWxpYnMvb3BlbnNzbC0w
LjkuNyApCgl3ZWJkYXY/ICgKCQlkZXYtbGlicy9saWJ4bWwyCgkJPj1kZXYtZGIvc3FsaXRlLTMK
CQlzeXMtZnMvZTJmc3Byb2dzCgkpCgl4YXR0cj8gKCBrZXJuZWxfbGludXg/ICggc3lzLWFwcHMv
YXR0ciApICkiCgpERVBFTkQ9IiR7UkRFUEVORH0KCWRvYz8gICggZGV2LXB5dGhvbi9kb2N1dGls
cyApCgl0ZXN0PyAoCgkJdmlydHVhbC9wZXJsLVRlc3QtSGFybmVzcwoJCWRldi1saWJzL2ZjZ2kK
CSkiCgojIHVwZGF0ZSBjZXJ0YWluIHBhcnRzIG9mIGxpZ2h0dHBkLmNvbmYgYmFzZWQgb24gY29u
ZGl0aW9uYWxzCnVwZGF0ZV9jb25maWcoKSB7Cglsb2NhbCBjb25maWc9Ii9ldGMvbGlnaHR0cGQv
bGlnaHR0cGQuY29uZiIKCgkjIGVuYWJsZSBwaHAvbW9kX2Zhc3RjZ2kgc2V0dGluZ3MKCXVzZSBw
aHAgJiYgXAoJCWRvc2VkICdzfCMuKlwoaW5jbHVkZS4qZmFzdGNnaS4qJFwpfFwxfCcgJHtjb25m
aWd9CgoJIyBlbmFibGUgc3RhdCgpIGNhY2hpbmcKCXVzZSBmYW0gJiYgXAoJCWRvc2VkICdzfCNc
KC4qc3RhdC1jYWNoZS4qJFwpfFwxfCcgJHtjb25maWd9Cn0KCiMgcmVtb3ZlIG5vbi1lc3NlbnRp
YWwgc3R1ZmYgKGZvciBVU0U9bWluaW1hbCkKcmVtb3ZlX25vbl9lc3NlbnRpYWwoKSB7Cglsb2Nh
bCBsaWJkaXI9IiR7RH0vdXNyLyQoZ2V0X2xpYmRpcikvJHtQTn0iCgoJIyB0ZXh0IGRvY3MKCXVz
ZSBkb2MgfHwgcm0gLWZyICR7RH0vdXNyL3NoYXJlL2RvYy8ke1BGfS90eHQKCgkjIG5vbi1lc3Nl
bnRpYWwgbW9kdWxlcwoJcm0gLWYgXAoJCSR7bGliZGlyfS9tb2Rfe2NvbXByZXNzLGV2aG9zdCxl
eHBpcmUscHJveHksc2NnaSxzZWNkb3dubG9hZCxzaW1wbGVfdmhvc3Qsc3RhdHVzLHNldGVudix0
cmlnZ2VyKix1c2VydHJhY2t9LioKCgkjIGFsbG93IHVzZXJzIHRvIGtlZXAgc29tZSBiYXNlZCBv
biBVU0UgZmxhZ3MKCXVzZSBwY3JlICAgIHx8IHJtIC1mICR7bGliZGlyfS9tb2Rfe3NzaSxyZXtk
aXJlY3Qsd3JpdGV9fS4qCgl1c2Ugd2ViZGF2ICB8fCBybSAtZiAke2xpYmRpcn0vbW9kX3dlYmRh
di4qCgl1c2UgbXlzcWwgICB8fCBybSAtZiAke2xpYmRpcn0vbW9kX215c3FsX3Zob3N0LioKCXVz
ZSBsdWEgICAgIHx8IHJtIC1mICR7bGliZGlyfS9tb2Rfe2NtbCxtYWduZXR9LioKCXVzZSBycmR0
b29sIHx8IHJtIC1mICR7bGliZGlyfS9tb2RfcnJkdG9vbC4qCgoJaWYgISB1c2UgZmFzdGNnaSA7
IHRoZW4KCQlybSAtZiAke2xpYmRpcn0vbW9kX2Zhc3RjZ2kuKiAke0R9L3Vzci9iaW4vc3Bhd24t
ZmNnaSBcCgkJCSR7RH0vdXNyL3NoYXJlL21hbi9tYW4xL3NwYXduLWZjZ2kuKgoJZmkKfQoKcGtn
X3NldHVwKCkgewoJaWYgISB1c2UgcGNyZSA7IHRoZW4KCQlld2FybiAiSXQgaXMgaGlnaGx5IHJl
Y29tbWVuZGVkIHRoYXQgeW91IGJ1aWxkICR7UE59IgoJCWV3YXJuICJ3aXRoIHBlcmwgcmVndWxh
ciBleHByZXNzaW9ucyBzdXBwb3J0IHZpYSBVU0U9cGNyZS4iCgkJZXdhcm4gIk90aGVyd2lzZSB5
b3UgbG9zZSBzdXBwb3J0IGZvciBzb21lIGNvcmUgb3B0aW9ucyBzdWNoIgoJCWV3YXJuICJhcyBj
b25kaXRpb25hbHMgYW5kIG1vZHVsZXMgc3VjaCBhcyBtb2RfcmV7d3JpdGUsZGlyZWN0fSIKCQll
d2FybiAiYW5kIG1vZF9zc2kuIgoJCWViZWVwIDUKCWZpCgoJdXNlIHBocCAmJiByZXF1aXJlX3Bo
cF93aXRoX3VzZSBjZ2kKCgllbmV3Z3JvdXAgbGlnaHR0cGQKCWVuZXd1c2VyIGxpZ2h0dHBkIC0x
IC0xIC92YXIvd3d3L2xvY2FsaG9zdC9odGRvY3MgbGlnaHR0cGQKfQoKc3JjX3VucGFjaygpIHsK
CXVucGFjayAke0F9CgljZCAke1N9CgoJRVBBVENIX1NVRkZJWD0iZGlmZiIgRVBBVENIX09QVFM9
Ii1sIiBlcGF0Y2ggJHtGSUxFU0RJUn0vJHtQVn0gfHwgZGllICJQYXRjaGluZyBmYWlsZWQhIgoK
CWVhdXRvcmVjb25mIHx8IGRpZQoKCSMgZGV2LXB5dGhvbi9kb2N1dGlscyBpbnN0YWxscyByc3Qy
aHRtbC5weSBub3QgcnN0Mmh0bWwKCXNlZCAtaSAtZSAnc3xcKHJzdDJodG1sXCl8XDEucHl8Zycg
ZG9jL01ha2VmaWxlLmluIHx8IFwKCQlkaWUgInNlZCBkb2MvTWFrZWZpbGUuaW4gZmFpbGVkIgoK
CSMgZml4IHR5cG8KCXNlZCAtaSAtZSAnc3xcKG91dHB1dF9jb250ZW50XClfXCh0eXBlXCl8XDFc
MnwnIGRvYy9jbWwudHh0IHx8IFwKCQlkaWUgInNlZCBkb2MvY21sLnR4dCBmYWlsZWQiCn0KCnNy
Y19jb21waWxlKCkgewoJZWNvbmYgLS1saWJkaXI9L3Vzci8kKGdldF9saWJkaXIpLyR7UE59IFwK
CQktLWVuYWJsZS1sZnMgXAoJCSQodXNlX2VuYWJsZSBpcHY2KSBcCgkJJCh1c2Vfd2l0aCBiemlw
MikgXAoJCSQodXNlX3dpdGggZmFtKSBcCgkJJCh1c2Vfd2l0aCBnZGJtKSBcCgkJJCh1c2Vfd2l0
aCBsdWEpIFwKCQkkKHVzZV93aXRoIGxkYXApIFwKCQkkKHVzZV93aXRoIG1lbWNhY2hlKSBcCgkJ
JCh1c2Vfd2l0aCBteXNxbCkgXAoJCSQodXNlX3dpdGggcGNyZSkgXAoJCSQodXNlX3dpdGggc3Ns
IG9wZW5zc2wpIFwKCQkkKHVzZV93aXRoIHdlYmRhdiB3ZWJkYXYtcHJvcHMpIFwKCQkkKHVzZV93
aXRoIHdlYmRhdiB3ZWJkYXYtbG9ja3MpIFwKCQkkKHVzZV93aXRoIHhhdHRyIGF0dHIpIFwKCQl8
fCBkaWUgImVjb25mIGZhaWxlZCIKCgllbWFrZSB8fCBkaWUgImVtYWtlIGZhaWxlZCIKCglpZiB1
c2UgZG9jIDsgdGhlbgoJCWVpbmZvICJCdWlsZGluZyBIVE1MIGRvY3VtZW50YXRpb24iCgkJY2Qg
ZG9jCgkJZW1ha2UgaHRtbCB8fCBkaWUgImZhaWxlZCB0byBidWlsZCBIVE1MIGRvY3VtZW50YXRp
b24iCglmaQp9CgpzcmNfaW5zdGFsbCgpIHsKCW1ha2UgREVTVERJUj0iJHtEfSIgaW5zdGFsbCB8
fCBkaWUgIm1ha2UgaW5zdGFsbCBmYWlsZWQiCgoJIyBpbml0IHNjcmlwdCBzdHVmZgoJbmV3aW5p
dGQgJHtGSUxFU0RJUn0vbGlnaHR0cGQuaW5pdGQtMS40LjEzLXIyIGxpZ2h0dHBkIHx8IGRpZQoJ
bmV3Y29uZmQgJHtGSUxFU0RJUn0vbGlnaHR0cGQuY29uZmQgbGlnaHR0cGQgfHwgZGllCgl1c2Ug
ZmFtICYmIGhhc192ZXJzaW9uIGFwcC1hZG1pbi9mYW0gJiYgXAoJCXNlZCAtaSAncy9hZnRlciBm
YW1kL25lZWQgZmFtZC9nJyAiJHtEfSIvZXRjL2luaXQuZC9saWdodHRwZAoKCWlmIHVzZSBwaHAg
fHwgdXNlIGZhc3RjZ2kgOyB0aGVuCgkJbmV3aW5pdGQgJHtGSUxFU0RJUn0vc3Bhd24tZmNnaS5p
bml0ZCBzcGF3bi1mY2dpIHx8IGRpZQoJCW5ld2NvbmZkICR7RklMRVNESVJ9L3NwYXduLWZjZ2ku
Y29uZmQgc3Bhd24tZmNnaSB8fCBkaWUKCWZpCgoJIyBjb25maWdzCglpbnNpbnRvIC9ldGMvbGln
aHR0cGQKCWRvaW5zICR7RklMRVNESVJ9L2NvbmYvbGlnaHR0cGQuY29uZgoJZG9pbnMgJHtGSUxF
U0RJUn0vY29uZi9taW1lLXR5cGVzLmNvbmYKCWRvaW5zICR7RklMRVNESVJ9L2NvbmYvbW9kX2Nn
aS5jb25mCgluZXdpbnMgJHtGSUxFU0RJUn0vY29uZi9tb2RfZmFzdGNnaS5jb25mLTEuNC4xMy1y
MiBtb2RfZmFzdGNnaS5jb25mCgkjIFNlY3VyZSBkaXJlY3RvcnkgZm9yIGZhc3RjZ2kgc29ja2V0
cwoJa2VlcGRpciAvdmFyL3J1bi9saWdodHRwZC8KCWZwZXJtcyAwNzUwIC92YXIvcnVuL2xpZ2h0
dHBkLwoJZm93bmVycyBsaWdodHRwZDpsaWdodHRwZCAvdmFyL3J1bi9saWdodHRwZC8KCgkjIHVw
ZGF0ZSBsaWdodHRwZC5jb25mIGRpcmVjdGl2ZXMgYmFzZWQgb24gY29uZGl0aW9uYWxzCgl1cGRh
dGVfY29uZmlnCgoJIyBkb2NzCglkb2RvYyBBVVRIT1JTIFJFQURNRSBORVdTIENoYW5nZUxvZyBk
b2MvKi5zaAoJbmV3ZG9jIGRvYy9saWdodHRwZC5jb25mIGxpZ2h0dHBkLmNvbmYuZGlzdHJpYgoK
CXVzZSBkb2MgJiYgZG9odG1sIC1yIGRvYy8qCgoJZG9jaW50byB0eHQKCWRvZG9jIGRvYy8qLnR4
dAoKCSMgbG9ncm90YXRlCglpbnNpbnRvIC9ldGMvbG9ncm90YXRlLmQKCW5ld2lucyAke0ZJTEVT
RElSfS9saWdodHRwZC5sb2dyb3RhdGUgbGlnaHR0cGQgfHwgZGllCgoJa2VlcGRpciAvdmFyL2x7
aWIsb2d9L2xpZ2h0dHBkIC92YXIvd3d3L2xvY2FsaG9zdC9odGRvY3MKCWZvd25lcnMgbGlnaHR0
cGQ6bGlnaHR0cGQgL3Zhci9se2liLG9nfS9saWdodHRwZAoJZnBlcm1zIDA3NTAgL3Zhci9se2li
LG9nfS9saWdodHRwZAoKCXVzZSBtaW5pbWFsICYmIHJlbW92ZV9ub25fZXNzZW50aWFsCn0KCnBr
Z19wb3N0aW5zdCAoKSB7CgllY2hvCglpZiBbWyAtZiAke1JPT1R9ZXRjL2NvbmYuZC9zcGF3bi1m
Y2dpLmNvbmYgXV0gOyB0aGVuCgkJZWluZm8gInNwYXduLWZjZ2kgaXMgbm93IGluY2x1ZGVkIHdp
dGggbGlnaHR0cGQiCgkJZWluZm8gInNwYXduLWZjZ2kncyBpbml0IHNjcmlwdCBjb25maWd1cmF0
aW9uIGlzIG5vdyBsb2NhdGVkIgoJCWVpbmZvICJhdCAvZXRjL2NvbmYuZC9zcGF3bi1mY2dpLiIK
CQllY2hvCglmaQoKCWlmIFtbIC1mICR7Uk9PVH1ldGMvbGlnaHR0cGQuY29uZiBdXSA7IHRoZW4K
CQlld2FybiAiQXMgb2YgbGlnaHR0cGQtMS40LjEsIEdlbnRvbyBoYXMgYSBjdXN0b21pemVkIGNv
bmZpZ3VyYXRpb24sIgoJCWV3YXJuICJ3aGljaCBpcyBub3cgbG9jYXRlZCBpbiAvZXRjL2xpZ2h0
dHBkLiAgUGxlYXNlIG1pZ3JhdGUgeW91ciIKCQlld2FybiAiZXhpc3RpbmcgY29uZmlndXJhdGlv
bi4iCgkJZWJlZXAgNQoJZmkKCglpZiB1c2UgZmFtIDsgdGhlbgoJCWVpbmZvICJSZW1lbWJlciB0
byByZS1lbWVyZ2UgbGlnaHR0cGQgc2hvdWxkIHlvdSBzd2l0Y2ggZnJvbSIKCQllaW5mbyAiYXBw
LWFkbWluL2ZhbWQgdG8gYXBwLWFkbWluL2dhbWluIG9yIHZpY2UgdmVyc2EuIgoJZmkKCWVjaG8K
fQo=
</data>        

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>124968</attachid>
            <date>2007-07-15 22:02 0000</date>
            <desc>07_all_lighttpd-1.4.15-duplicated_headers_with_folding_crash.diff</desc>
            <filename>07_all_lighttpd-1.4.15-duplicated_headers_with_folding_crash.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IHNyYy9yZXF1ZXN0LmMKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gc3JjL3JlcXVlc3QuYwkocmV2aXNp
b24gMTg2OCkKKysrIHNyYy9yZXF1ZXN0LmMJKHJldmlzaW9uIDE4NzApCkBAIC0yODQsOCArMjg0
LDYgQEAKIAogCWludCBkb25lID0gMDsKIAotCWRhdGFfc3RyaW5nICpkcyA9IE5VTEw7Ci0KIAkv
KgogCSAqIFJlcXVlc3Q6ICJeKEdFVHxQT1NUfEhFQUQpIChbXiBdKyhcXD9bXiBdK3wpKSAoSFRU
UC8xXFwuWzAxXSkkIgogCSAqIE9wdGlvbiA6ICJeKFstYS16QS1aXSspOiAoLispJCIKQEAgLTcx
NSwxMiArNzEzLDI0IEBACiAJCQlzd2l0Y2goKmN1cikgewogCQkJY2FzZSAnXHInOgogCQkJCWlm
IChjb24tPnBhcnNlX3JlcXVlc3QtPnB0cltpKzFdID09ICdcbicpIHsKKwkJCQkJZGF0YV9zdHJp
bmcgKmRzID0gTlVMTDsKKwogCQkJCQkvKiBFbmQgb2YgSGVhZGVybGluZSAqLwogCQkJCQljb24t
PnBhcnNlX3JlcXVlc3QtPnB0cltpXSA9ICdcMCc7CiAJCQkJCWNvbi0+cGFyc2VfcmVxdWVzdC0+
cHRyW2krMV0gPSAnXDAnOwogCiAJCQkJCWlmIChpbl9mb2xkaW5nKSB7Ci0JCQkJCQlpZiAoIWRz
KSB7CisJCQkJCQlidWZmZXIgKmtleV9iOworCQkJCQkJLyoqCisJCQkJCQkgKiB3ZSB1c2UgYSBl
dmlsIGhhY2sgdG8gaGFuZGxlIHRoZSBsaW5lLWZvbGRpbmcKKwkJCQkJCSAqIAorCQkJCQkJICog
QXMgYXJyYXlfaW5zZXJ0X3VuaXF1ZSgpIGRlbGV0ZXMgJ2RzJyBpbiB0aGUgY2FzZSBvZiBhIGR1
cGxpY2F0ZQorCQkJCQkJICogZHMgcG9pbnRzIHNvbWV3aGVyZSBhbmQgd2UgZ2V0IGEgZXZpbCBj
cmFzaC4gQXMgYSBzb2x1dGlvbiB3ZSBrZWVwIHRoZSBvbGQKKwkJCQkJCSAqICJrZXkiIGFuZCBn
ZXQgdGhlIGN1cnJlbnQgdmFsdWUgZnJvbSB0aGUgaGFzaCBhbmQgYXBwZW5kIHVzCisJCQkJCQkg
KgorCQkJCQkJICogKi8KKworCQkJCQkJaWYgKCFrZXkgfHwgIWtleV9sZW4pIHsKIAkJCQkJCQkv
KiA0MDAgKi8KIAogCQkJCQkJCWlmIChzcnYtPnNydmNvbmYubG9nX3JlcXVlc3RfaGVhZGVyX29u
X2Vycm9yKSB7CkBAIC03MzcsNyArNzQ3LDE1IEBACiAJCQkJCQkJY29uLT5yZXNwb25zZS5rZWVw
X2FsaXZlID0gMDsKIAkJCQkJCQlyZXR1cm4gMDsKIAkJCQkJCX0KLQkJCQkJCWJ1ZmZlcl9hcHBl
bmRfc3RyaW5nKGRzLT52YWx1ZSwgdmFsdWUpOworCisJCQkJCQlrZXlfYiA9IGJ1ZmZlcl9pbml0
KCk7CisJCQkJCQlidWZmZXJfY29weV9zdHJpbmdfbGVuKGtleV9iLCBrZXksIGtleV9sZW4pOwor
CisJCQkJCQlpZiAoTlVMTCAhPSAoZHMgPSAoZGF0YV9zdHJpbmcgKilhcnJheV9nZXRfZWxlbWVu
dChjb24tPnJlcXVlc3QuaGVhZGVycywga2V5X2ItPnB0cikpKSB7CisJCQkJCQkJYnVmZmVyX2Fw
cGVuZF9zdHJpbmcoZHMtPnZhbHVlLCB2YWx1ZSk7CisJCQkJCQl9CisKKwkJCQkJCWJ1ZmZlcl9m
cmVlKGtleV9iKTsKIAkJCQkJfSBlbHNlIHsKIAkJCQkJCWludCBzX2xlbjsKIAkJCQkJCWtleSA9
IGNvbi0+cGFyc2VfcmVxdWVzdC0+cHRyICsgZmlyc3Q7CkBAIC05NjksNyArOTg3LDEyIEBACiAJ
CQkJCWZpcnN0ID0gaSsxOwogCQkJCQlpc19rZXkgPSAxOwogCQkJCQl2YWx1ZSA9IDA7Ci0JCQkJ
CWtleV9sZW4gPSAwOworI2lmIDAKKwkJCQkJLyoqCisJCQkJCSAqIGZvciBCdWcgMTIzMCBrZWVw
IHRoZSBrZXlfbGVuIGEgbGl2ZQorCQkJCQkgKi8KKwkJCQkJa2V5X2xlbiA9IDA7IAorI2VuZGlm
CiAJCQkJCWluX2ZvbGRpbmcgPSAwOwogCQkJCX0gZWxzZSB7CiAJCQkJCWlmIChzcnYtPnNydmNv
bmYubG9nX3JlcXVlc3RfaGVhZGVyX29uX2Vycm9yKSB7CkluZGV4OiB0ZXN0cy9jb3JlLXJlcXVl
c3QudAo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09Ci0tLSB0ZXN0cy9jb3JlLXJlcXVlc3QudAkocmV2aXNpb24gMTg2OCkK
KysrIHRlc3RzL2NvcmUtcmVxdWVzdC50CShyZXZpc2lvbiAxODcwKQpAQCAtOCw3ICs4LDcgQEAK
IAogdXNlIHN0cmljdDsKIHVzZSBJTzo6U29ja2V0OwotdXNlIFRlc3Q6Ok1vcmUgdGVzdHMgPT4g
MzM7Cit1c2UgVGVzdDo6TW9yZSB0ZXN0cyA9PiAzNjsKIHVzZSBMaWdodHlUZXN0OwogCiBteSAk
dGYgPSBMaWdodHlUZXN0LT5uZXcoKTsKQEAgLTI3Myw2ICsyNzMsMzggQEAKICR0LT57UkVTUE9O
U0V9ID0gWyB7ICdIVFRQLVByb3RvY29sJyA9PiAnSFRUUC8xLjAnLCAnSFRUUC1TdGF0dXMnID0+
IDIwMCB9IF07CiBvaygkdGYtPmhhbmRsZV9odHRwKCR0KSA9PSAwLCAndXBwZXJjYXNlIGZpbGVu
YW1lcycpOwogCiskdC0+e1JFUVVFU1R9ICA9ICggPDxFT0YKK0dFVCAvIEhUVFAvMS4wCitMb2Nh
dGlvbjogZm9vCitMb2NhdGlvbjogZm9vYmFyCisgIGJhegorRU9GCisgKTsKKyR0LT57UkVTUE9O
U0V9ID0gWyB7ICdIVFRQLVByb3RvY29sJyA9PiAnSFRUUC8xLjAnLCAnSFRUUC1TdGF0dXMnID0+
IDIwMCB9IF07CitvaygkdGYtPmhhbmRsZV9odHRwKCR0KSA9PSAwLCAnIzEyMzIgLSBkdXBsaWNh
dGUgaGVhZGVycyB3aXRoIGxpbmUtd3JhcHBpbmcnKTsKIAorJHQtPntSRVFVRVNUfSAgPSAoIDw8
RU9GCitHRVQgLyBIVFRQLzEuMAorTG9jYXRpb246IAorTG9jYXRpb246IGZvb2JhcgorICBiYXoK
K0VPRgorICk7CiskdC0+e1JFU1BPTlNFfSA9IFsgeyAnSFRUUC1Qcm90b2NvbCcgPT4gJ0hUVFAv
MS4wJywgJ0hUVFAtU3RhdHVzJyA9PiAyMDAgfSBdOworb2soJHRmLT5oYW5kbGVfaHR0cCgkdCkg
PT0gMCwgJyMxMjMyIC0gZHVwbGljYXRlIGhlYWRlcnMgd2l0aCBsaW5lLXdyYXBwaW5nIC0gdGVz
dCAyJyk7CisKKyR0LT57UkVRVUVTVH0gID0gKCA8PEVPRgorR0VUIC8gSFRUUC8xLjAKK0E6IAor
TG9jYXRpb246IGZvb2JhcgorICBiYXoKK0VPRgorICk7CiskdC0+e1JFU1BPTlNFfSA9IFsgeyAn
SFRUUC1Qcm90b2NvbCcgPT4gJ0hUVFAvMS4wJywgJ0hUVFAtU3RhdHVzJyA9PiAyMDAgfSBdOwor
b2soJHRmLT5oYW5kbGVfaHR0cCgkdCkgPT0gMCwgJyMxMjMyIC0gZHVwbGljYXRlIGhlYWRlcnMg
d2l0aCBsaW5lLXdyYXBwaW5nIC0gdGVzdCAzJyk7CisKKworCisKIG9rKCR0Zi0+c3RvcF9wcm9j
ID09IDAsICJTdG9wcGluZyBsaWdodHRwZCIpOwogCg==
</data>        

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>124969</attachid>
            <date>2007-07-15 22:02 0000</date>
            <desc>08_all_lighttpd-1.4.15-mod_access_bypass.diff</desc>
            <filename>08_all_lighttpd-1.4.15-mod_acces_bypass.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IHNyYy9tb2RfYWNjZXNzLmMKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gc3JjL21vZF9hY2Nlc3MuYwko
cmV2aXNpb24gMTg3MCkKKysrIHNyYy9tb2RfYWNjZXNzLmMJKHJldmlzaW9uIDE4NzEpCkBAIC0x
MTEsNiArMTExLDE1IEBACiB9CiAjdW5kZWYgUEFUQ0gKIAorLyoqCisgKiBVUkkgaGFuZGxlcgor
ICoKKyAqIHdlIHdpbGwgZ2V0IGNhbGxlZCB0d2ljZToKKyAqIC0gYWZ0ZXIgdGhlIGNsZWFuIHVw
IG9mIHRoZSBVUkwgYW5kIAorICogLSBhZnRlciB0aGUgcGF0aGluZm8gY2hlY2tzIGFyZSBkb25l
CisgKgorICogdGhpcyBoYW5kbGVzIHRoZSBpc3N1ZSBvZiB0cmFpbGluZyBzbGFzaGVzCisgKi8K
IFVSSUhBTkRMRVJfRlVOQyhtb2RfYWNjZXNzX3VyaV9oYW5kbGVyKSB7CiAJcGx1Z2luX2RhdGEg
KnAgPSBwX2Q7CiAJaW50IHNfbGVuOwpAQCAtMTIyLDI4ICsxMzEsNDEgQEAKIAogCXNfbGVuID0g
Y29uLT51cmkucGF0aC0+dXNlZCAtIDE7CiAKKwlpZiAoY29uLT5jb25mLmxvZ19yZXF1ZXN0X2hh
bmRsaW5nKSB7CisgCQlsb2dfZXJyb3Jfd3JpdGUoc3J2LCBfX0ZJTEVfXywgX19MSU5FX18sICJz
IiwgCisJCQkJIi0tIG1vZF9hY2Nlc3NfdXJpX2hhbmRsZXIgY2FsbGVkIik7CisJfQorCiAJZm9y
IChrID0gMDsgayA8IHAtPmNvbmYuYWNjZXNzX2RlbnktPnVzZWQ7IGsrKykgewogCQlkYXRhX3N0
cmluZyAqZHMgPSAoZGF0YV9zdHJpbmcgKilwLT5jb25mLmFjY2Vzc19kZW55LT5kYXRhW2tdOwog
CQlpbnQgY3RfbGVuID0gZHMtPnZhbHVlLT51c2VkIC0gMTsKKwkJaW50IGRlbmllZCA9IDA7CiAK
KwogCQlpZiAoY3RfbGVuID4gc19sZW4pIGNvbnRpbnVlOwotCiAJCWlmIChkcy0+dmFsdWUtPnVz
ZWQgPT0gMCkgY29udGludWU7CiAKIAkJLyogaWYgd2UgaGF2ZSBhIGNhc2UtaW5zZW5zaXRpdmUg
RlMgd2UgaGF2ZSB0byBsb3dlci1jYXNlIHRoZSBVUkkgaGVyZSB0b28gKi8KIAogCQlpZiAoY29u
LT5jb25mLmZvcmNlX2xvd2VyY2FzZV9maWxlbmFtZXMpIHsKIAkJCWlmICgwID09IHN0cm5jYXNl
Y21wKGNvbi0+dXJpLnBhdGgtPnB0ciArIHNfbGVuIC0gY3RfbGVuLCBkcy0+dmFsdWUtPnB0ciwg
Y3RfbGVuKSkgewotCQkJCWNvbi0+aHR0cF9zdGF0dXMgPSA0MDM7Ci0KLQkJCQlyZXR1cm4gSEFO
RExFUl9GSU5JU0hFRDsKKwkJCQlkZW5pZWQgPSAxOwogCQkJfQogCQl9IGVsc2UgewogCQkJaWYg
KDAgPT0gc3RybmNtcChjb24tPnVyaS5wYXRoLT5wdHIgKyBzX2xlbiAtIGN0X2xlbiwgZHMtPnZh
bHVlLT5wdHIsIGN0X2xlbikpIHsKLQkJCQljb24tPmh0dHBfc3RhdHVzID0gNDAzOworCQkJCWRl
bmllZCA9IDE7CisJCQl9CisJCX0KIAotCQkJCXJldHVybiBIQU5ETEVSX0ZJTklTSEVEOworCQlp
ZiAoZGVuaWVkKSB7CisJCQljb24tPmh0dHBfc3RhdHVzID0gNDAzOworCisJCQlpZiAoY29uLT5j
b25mLmxvZ19yZXF1ZXN0X2hhbmRsaW5nKSB7CisJIAkJCWxvZ19lcnJvcl93cml0ZShzcnYsIF9f
RklMRV9fLCBfX0xJTkVfXywgInNiIiwgCisJCQkJCSJ1cmwgZGVuaWVkIGFzIHdlIG1hdGNoOiIs
IGRzLT52YWx1ZSk7CiAJCQl9CisKKwkJCXJldHVybiBIQU5ETEVSX0ZJTklTSEVEOwogCQl9CiAJ
fQogCkBAIC0xNTgsNyArMTgwLDggQEAKIAogCXAtPmluaXQgICAgICAgID0gbW9kX2FjY2Vzc19p
bml0OwogCXAtPnNldF9kZWZhdWx0cyA9IG1vZF9hY2Nlc3Nfc2V0X2RlZmF1bHRzOwotCXAtPmhh
bmRsZV91cmlfY2xlYW4gID0gbW9kX2FjY2Vzc191cmlfaGFuZGxlcjsKKwlwLT5oYW5kbGVfdXJp
X2NsZWFuID0gbW9kX2FjY2Vzc191cmlfaGFuZGxlcjsKKwlwLT5oYW5kbGVfc3VicmVxdWVzdF9z
dGFydCAgPSBtb2RfYWNjZXNzX3VyaV9oYW5kbGVyOwogCXAtPmNsZWFudXAgICAgID0gbW9kX2Fj
Y2Vzc19mcmVlOwogCiAJcC0+ZGF0YSAgICAgICAgPSBOVUxMOwpJbmRleDogdGVzdHMvbW9kLWFj
Y2Vzcy50Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT0KLS0tIHRlc3RzL21vZC1hY2Nlc3MudAkocmV2aXNpb24gMTg3MCkK
KysrIHRlc3RzL21vZC1hY2Nlc3MudAkocmV2aXNpb24gMTg3MSkKQEAgLTgsNyArOCw3IEBACiAK
IHVzZSBzdHJpY3Q7CiB1c2UgSU86OlNvY2tldDsKLXVzZSBUZXN0OjpNb3JlIHRlc3RzID0+IDM7
Cit1c2UgVGVzdDo6TW9yZSB0ZXN0cyA9PiA0OwogdXNlIExpZ2h0eVRlc3Q7CiAKIG15ICR0ZiA9
IExpZ2h0eVRlc3QtPm5ldygpOwpAQCAtMjMsNSArMjMsMTIgQEAKICR0LT57UkVTUE9OU0V9ID0g
WyB7ICdIVFRQLVByb3RvY29sJyA9PiAnSFRUUC8xLjAnLCAnSFRUUC1TdGF0dXMnID0+IDQwMyB9
IF07CiBvaygkdGYtPmhhbmRsZV9odHRwKCR0KSA9PSAwLCAnZm9yYmlkIGFjY2VzcyB0byAuLi5+
Jyk7CiAKKyR0LT57UkVRVUVTVH0gID0gKCA8PEVPRgorR0VUIC9pbmRleC5odG1sfi8gSFRUUC8x
LjAKK0VPRgorICk7CiskdC0+e1JFU1BPTlNFfSA9IFsgeyAnSFRUUC1Qcm90b2NvbCcgPT4gJ0hU
VFAvMS4wJywgJ0hUVFAtU3RhdHVzJyA9PiA0MDMgfSBdOworb2soJHRmLT5oYW5kbGVfaHR0cCgk
dCkgPT0gMCwgJyMxMjMwIC0gZm9yYmlkIGFjY2VzcyB0byAuLi5+IC0gdHJhaWxpbmcgc2xhc2gn
KTsKKwogb2soJHRmLT5zdG9wX3Byb2MgPT0gMCwgIlN0b3BwaW5nIGxpZ2h0dHBkIik7CiAKSW5k
ZXg6IHRlc3RzL3ByZXBhcmUuc2gKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gdGVzdHMvcHJlcGFyZS5zaAkocmV2
aXNpb24gMTg3MCkKKysrIHRlc3RzL3ByZXBhcmUuc2gJKHJldmlzaW9uIDE4NzEpCkBAIC0yNSw2
ICsyNSw3IEBACiAjIGNvcHkgZXZlcnl0aGluZyBpbnRvIHRoZSByaWdodCBwbGFjZXMKIGNwICRz
cmNkaXIvZG9jcm9vdC93d3cvKi5odG1sIFwKICAgICRzcmNkaXIvZG9jcm9vdC93d3cvKi5waHAg
XAorICAgJHNyY2Rpci9kb2Nyb290L3d3dy8qLmh0bWx+IFwKICAgICRzcmNkaXIvZG9jcm9vdC93
d3cvKi5wbCBcCiAgICAkc3JjZGlyL2RvY3Jvb3Qvd3d3LyouZmNnaSBcCiAgICAkc3JjZGlyL2Rv
Y3Jvb3Qvd3d3Lyouc2h0bWwgXApJbmRleDogdGVzdHMvZG9jcm9vdC93d3cvaW5kZXguaHRtbH4K
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PQpJbmRleDogdGVzdHMvZG9jcm9vdC93d3cvTWFrZWZpbGUuYW0KPT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PQotLS0gdGVzdHMvZG9jcm9vdC93d3cvTWFrZWZpbGUuYW0JKHJldmlzaW9uIDE4NzApCisrKyB0
ZXN0cy9kb2Nyb290L3d3dy9NYWtlZmlsZS5hbQkocmV2aXNpb24gMTg3MSkKQEAgLTEsNSArMSw1
IEBACiBFWFRSQV9ESVNUPWNnaS5waHAgY2dpLnBsIGR1bW15ZGlyIGluZGV4Lmh0bWwgaW5kZXgu
dHh0IHBocGluZm8ucGhwIFwKIAkgICByZWRpcmVjdC5waHAgY2dpLXBhdGhpbmZvLnBsIGdldC1l
bnYucGhwIGdldC1zZXJ2ZXItZW52LnBocCBcCiAJICAgbnBoLXN0YXR1cy5wbCBwcmVmaXguZmNn
aSBnZXQtaGVhZGVyLnBsIHNzaS5zaHRtbCBnZXQtcG9zdC1sZW4ucGwgXAotCSAgIGV4ZWMtZGF0
ZS5zaHRtbAorCSAgIGV4ZWMtZGF0ZS5zaHRtbCBpbmRleC5odG1sfgogU1VCRElSUz1nbyBpbmRl
eGZpbGUgZXhwaXJlCg==
</data>        

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>124971</attachid>
            <date>2007-07-15 22:05 0000</date>
            <desc>09_all_lighttpd-1.4.15-mod_fastcgi_local_dos.diff</desc>
            <filename>09_all_lighttpd-1.4.15-mod_fastcgi_local_dos.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">SW5kZXg6IHNyYy9tb2RfZmFzdGNnaS5jCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIHNyYy9tb2RfZmFzdGNnaS5j
CShyZXZpc2lvbiAxODc4KQorKysgc3JjL21vZF9mYXN0Y2dpLmMJKHJldmlzaW9uIDE4NzkpCkBA
IC0yNDQwLDcgKzI0NDAsNiBAQAogCQliLT51c2VkID0gciArIDE7IC8qIG9uZSBleHRyYSBmb3Ig
dGhlIGZha2UgXDAgKi8KIAkJYi0+cHRyW2ItPnVzZWQgLSAxXSA9ICdcMCc7CiAJfSBlbHNlIHsK
LQkJaWYgKGVycm5vID09IEVBR0FJTikgcmV0dXJuIDA7CiAJCWxvZ19lcnJvcl93cml0ZShzcnYs
IF9fRklMRV9fLCBfX0xJTkVfXywgInNzZHNiIiwKIAkJCQkidW5leHBlY3RlZCBlbmQtb2YtZmls
ZSAocGVyaGFwcyB0aGUgZmFzdGNnaSBwcm9jZXNzIGRpZWQpOiIsCiAJCQkJInBpZDoiLCBwcm9j
LT5waWQsCg==
</data>        

          </attachment>
    </bug>

</bugzilla>