|
|||||||||||
|
Bug#462458: apache2: SSL renegotiation does not work on POST requests in certain configurations
From: Garrett Wollman <wollman(at)csail.mit.edu>
Date: Thu Jan 24 2008 - 18:20:32 EST
When mod_fastcgi and mod_action are used (for example, to implement PHP4 and PHP5 in the same server), data from POST requests which is buffered during SSL renegotiation is not reinjected correctly through the filter chain. (Technically, anything that causes Apache to do an internal redirect on a POST request under SSL renegotiation can cause this bug to surface.) This bug was reported upstream as ASF Bugzilla Bug 43738 (<http://issues.apache.org/bugzilla/show_bug.cgi?id=43738>), and has been fixed in the Apache development line and in the 2.2 branch for a future release (Apache SVN revision 608787, <http://svn.apache.org/viewvc?view=rev&revision=608787>).
Versions of packages apache2 depends on: ii apache2-mpm-prefork 2.2.3-4+etch3 Traditional model for Apache HTTPD apache2 recommends no packages.
-- This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 03:00:17 EDT |
||||||||||
|
|||||||||||