diff options
Diffstat (limited to 'www')
-rw-r--r-- | www/apache21/files/patch-secfix-CAN-2005-3352 | 2 | ||||
-rw-r--r-- | www/apache22/files/patch-secfix-CAN-2005-3352 | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/www/apache21/files/patch-secfix-CAN-2005-3352 b/www/apache21/files/patch-secfix-CAN-2005-3352 index 092c55043d44..4afe7d978d43 100644 --- a/www/apache21/files/patch-secfix-CAN-2005-3352 +++ b/www/apache21/files/patch-secfix-CAN-2005-3352 @@ -28,7 +28,7 @@ referer = apr_table_get(r->headers_in, "Referer"); if (referer && *referer) { - return apr_pstrdup(r->pool, referer); -+ return apr_escape_html(r->pool, referer); ++ return ap_escape_html(r->pool, referer); } else { /* XXX: This used to do *value = '\0'; ... which is totally bogus diff --git a/www/apache22/files/patch-secfix-CAN-2005-3352 b/www/apache22/files/patch-secfix-CAN-2005-3352 index cc97428d6b80..ec323c26da5a 100644 --- a/www/apache22/files/patch-secfix-CAN-2005-3352 +++ b/www/apache22/files/patch-secfix-CAN-2005-3352 @@ -5,7 +5,7 @@ referer = apr_table_get(r->headers_in, "Referer"); if (referer && *referer) { - return apr_pstrdup(r->pool, referer); -+ return apr_escape_html(r->pool, referer); ++ return ap_escape_html(r->pool, referer); } else { /* XXX: This used to do *value = '\0'; ... which is totally bogus |