Overview
Request 205966 accepted
- update to 2.3.9:
+ obsoletes apache2-mod_fcgid-CVE-2013-4365-bnc844935.diff
and fixes CVE-2013-4365 [bnc#844935] (heap overflow).
The heap overflow discovery and fix was done by
Robert Matthews .
+ quoting and spaces parsing correction for FcgidWrapper directive
and commandline options.
+ logging improvements for access controls
+ remove redundant processing of Location headers when running in
FCGI_AUTHORIZER mode
- Intermediate fix for openSUSE:Factory eg. openSUSE:13.1:
apache2-mod_fcgid-CVE-2013-4365-bnc844935.diff fixes a heap
overflow identified by CVE-2013-4365 [bnc#844935].
This patch will be obsoleted by the next version update (to
2.3.9 or higher).
Request History
draht created request
- update to 2.3.9:
+ obsoletes apache2-mod_fcgid-CVE-2013-4365-bnc844935.diff
and fixes CVE-2013-4365 [bnc#844935] (heap overflow).
The heap overflow discovery and fix was done by
Robert Matthews .
+ quoting and spaces parsing correction for FcgidWrapper directive
and commandline options.
+ logging improvements for access controls
+ remove redundant processing of Location headers when running in
FCGI_AUTHORIZER mode
- Intermediate fix for openSUSE:Factory eg. openSUSE:13.1:
apache2-mod_fcgid-CVE-2013-4365-bnc844935.diff fixes a heap
overflow identified by CVE-2013-4365 [bnc#844935].
This patch will be obsoleted by the next version update (to
2.3.9 or higher).
factory-auto added a reviewer
Please review sources
factory-auto accepted review
Check script succeeded
factory-auto added a reviewer
Please review build success
licensedigger accepted review
{"approve": "preliminary, version number changed"}
factory-repo-checker accepted review
Builds for repo openSUSE_Factory
dimstar declined request
In the 'intermedite' fix you mention to add a patch; which obviously (from this single commit) gets dropped again with the update to 2.3.9... but said drop is not mentioned.
Please see
http://en.opensuse.org/openSUSE:Packaging_Patches_guidelines#Patch_live_cycle
=> Added / removed patches need to be mentioned by name in .changes, in
order to get a full trail of life cycles.
dimstar added a reviewer
My bad.. it IS there..
dimstar approved review
sorry for the noise.. in fact, the drop of the patch is mentioned...
dimstar accepted review
sorry for the noise.. in fact, the drop of the patch is mentioned...
coolo accepted request
checkin to openSUSE:Factory only