Bug 18881 - mod_rewrite bug allows access despite deny/allow filters
Summary: mod_rewrite bug allows access despite deny/allow filters
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: apache (Show other bugs)
(Show other bugs)
Version: 7.0
Hardware: i386 Linux
high
medium
Target Milestone: ---
Assignee: Nalin Dahyabhai
QA Contact: Dale Lovelace
URL:
Whiteboard:
Keywords: Security
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2000-10-11 10:51 UTC by Frank Ch. Eigler
Modified: 2007-03-27 03:36 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2000-10-16 04:09:14 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
phhttpd-eapi patch fot apache 1.3.14 mod ssl 2.7.1 (7.13 KB, patch)
2000-10-16 04:09 UTC, Arenas Belon, Carlo Marcelo
no flags Details | Diff

Description Frank Ch. Eigler 2000-10-11 10:51:04 UTC
Please see the recent bugtraq announcement.

Comment 1 Pekka Savola 2000-10-13 18:14:52 UTC
apache-1.3.14 is out.  This fixes this and other problems too, including a mass virtual hosting security issue.

Comment 2 Arenas Belon, Carlo Marcelo 2000-10-16 04:07:04 UTC
apache 1.3.14 with mod_ssl 2.7.1-1.3.14 needs a new phhttpd-eapi patch and a
small change on apache.spec

both patches added as attachment.

a final RPM/SRPM build with those patches is available from :
ftp://sajino.terra.com.pe/pub/linux/redhat/carenas/7.0/

Comment 3 Arenas Belon, Carlo Marcelo 2000-10-16 04:09:14 UTC
Created attachment 4188 [details]
phhttpd-eapi patch fot apache 1.3.14 mod ssl 2.7.1


Note You need to log in before you can comment on or make changes to this bug.