diff options
author | clement <clement@FreeBSD.org> | 2006-05-01 19:33:17 +0800 |
---|---|---|
committer | clement <clement@FreeBSD.org> | 2006-05-01 19:33:17 +0800 |
commit | 9c4b9bb391e4f46ced6db3a596b1b0aeb2cce431 (patch) | |
tree | 7a9156201f5483941543bbe3686d153f95402d38 /www | |
parent | f0874b75bf6b3dc3678b3bd94ca896a6d1c8cea9 (diff) | |
download | freebsd-ports-gnome-9c4b9bb391e4f46ced6db3a596b1b0aeb2cce431.tar.gz freebsd-ports-gnome-9c4b9bb391e4f46ced6db3a596b1b0aeb2cce431.tar.zst freebsd-ports-gnome-9c4b9bb391e4f46ced6db3a596b1b0aeb2cce431.zip |
Oops I forgot to "cvs rm" a secfix
Spotted by: krion
Diffstat (limited to 'www')
-rw-r--r-- | www/apache20/files/patch-secfix-CAN-2005-3352 | 35 |
1 files changed, 0 insertions, 35 deletions
diff --git a/www/apache20/files/patch-secfix-CAN-2005-3352 b/www/apache20/files/patch-secfix-CAN-2005-3352 deleted file mode 100644 index 895e30345d6b..000000000000 --- a/www/apache20/files/patch-secfix-CAN-2005-3352 +++ /dev/null @@ -1,35 +0,0 @@ ---- modules/mappers/mod_imap.c (original) -+++ modules/mappers/mod_imap.c Mon Dec 12 08:41:53 2005 -@@ -342,7 +342,7 @@ - if (!strcasecmp(value, "referer")) { - referer = apr_table_get(r->headers_in, "Referer"); - if (referer && *referer) { -- return apr_pstrdup(r->pool, referer); -+ return ap_escape_html(r->pool, referer); - } - else { - /* XXX: This used to do *value = '\0'; ... which is totally bogus - ---- server/util.c (original) -+++ server/util.c Mon Dec 12 08:41:53 2005 -@@ -1762,6 +1762,8 @@ - j += 3; - else if (s[i] == '&') - j += 4; -+ else if (s[i] == '"') -+ j += 5; - - if (j == 0) - return apr_pstrmemdup(p, s, i); -@@ -1779,6 +1781,10 @@ - else if (s[i] == '&') { - memcpy(&x[j], "&", 5); - j += 4; -+ } -+ else if (s[i] == '"') { -+ memcpy(&x[j], """, 6); -+ j += 5; - } - else - x[j] = s[i]; - |