The fix for this went into 2.2.22, so we don't need to keep 25_all-apply_to_2.2.21-CVE-2011-3368.patch around. Changes with Apache 2.2.22 *) SECURITY: CVE-2011-3368 (cve.mitre.org) Reject requests where the request-URI does not match the HTTP specification, preventing unexpected expansion of target URLs in some reverse proxy configurations. [Joe Orton]
Thanks for the report. http://git.overlays.gentoo.org/gitweb/?p=proj/apache.git;a=commitdiff;h=68bf261f5deea91855076a07330793f455475242 This will be in the next gentoo-apache tarball rollout. Please keep this bug open until a fixed apache is in portage.
Fixed in apache-2.2.27-r4 and apache-2.4.10-r1