Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 511656 - www-servers/apache: patch for CVE-2011-3368 is obsolete in all supported versions
Summary: www-servers/apache: patch for CVE-2011-3368 is obsolete in all supported vers...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Lars Wendler (Polynomial-C) (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-28 01:27 UTC by Michael Orlitzky
Modified: 2014-07-31 11:37 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Orlitzky gentoo-dev 2014-05-28 01:27:02 UTC
The fix for this went into 2.2.22, so we don't need to keep 25_all-apply_to_2.2.21-CVE-2011-3368.patch around.

Changes with Apache 2.2.22

  *) SECURITY: CVE-2011-3368 (cve.mitre.org)
     Reject requests where the request-URI does not match the HTTP
     specification, preventing unexpected expansion of target URLs in
     some reverse proxy configurations.  [Joe Orton]
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-05-28 07:43:16 UTC
Thanks for the report.

http://git.overlays.gentoo.org/gitweb/?p=proj/apache.git;a=commitdiff;h=68bf261f5deea91855076a07330793f455475242

This will be in the next gentoo-apache tarball rollout. Please keep this bug open until a fixed apache is in portage.
Comment 2 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-07-31 11:37:25 UTC
Fixed in apache-2.2.27-r4 and apache-2.4.10-r1