Mantis - apache2
Viewing Issue Advanced Details
5142 upgrade minor N/A 2014-01-20 13:00 2014-02-22 11:38
burger99  
dam  
normal  
closed  
fixed  
none    
none  
0005142: Security issues
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

Newest version available is 2.2.26
Issue History
2014-01-20 13:00 burger99 New Issue
2014-02-03 13:18 dam Status new => assigned
2014-02-03 13:18 dam Assigned To => dam
2014-02-03 17:06 dam Note Added: 0010697
2014-02-03 17:06 dam Status assigned => feedback
2014-02-22 11:38 dam Note Added: 0010730
2014-02-22 11:38 dam Status feedback => closed
2014-02-22 11:38 dam Resolution open => fixed

Notes
(0010697)
dam   
2014-02-03 17:06   
I made an experimental package which will show up soon here: http://buildfarm.opencsw.org/experimental.html#apache-2.2.26 [^]
Please give it a try and let me know if you are happy with it.
(0010730)
dam   
2014-02-22 11:38   
Apache 2.2.26,REV=2014.02.07 has been pushed to unstable/.