From c52e748415f441ca2dc6f5718d9e74042dee4abe1294a840b29c4feeb892fd6a Mon Sep 17 00:00:00 2001 From: OBS User buildservice-autocommit Date: Tue, 30 Nov 2010 23:13:47 +0000 Subject: [PATCH 1/2] Updating link to change in openSUSE:Factory/apache2-mod_perl revision 13.0 OBS-URL: https://build.opensuse.org/package/show/Apache:Modules/apache2-mod_perl?expand=0&rev=cd145c417a9b3bd41130cbdcdf9b7557 --- mod_perl.xpm | 80 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 80 insertions(+) create mode 100644 mod_perl.xpm diff --git a/mod_perl.xpm b/mod_perl.xpm new file mode 100644 index 0000000..af2ca05 --- /dev/null +++ b/mod_perl.xpm @@ -0,0 +1,80 @@ +/* XPM */ +static char *mod_perl[] = { +/* width height num_colors chars_per_pixel */ +" 90 30 43 1", +/* colors */ +". c #ffffff", +"# c #080808", +"a c #101010", +"b c #181818", +"c c #212121", +"d c #292929", +"e c #313131", +"f c #393939", +"g c #424242", +"h c #4a4a4a", +"i c #525252", +"j c #5a5a5a", +"k c #636363", +"l c #6b6b6b", +"m c #737373", +"n c #7b7b7b", +"o c #848484", +"p c #8c8c8c", +"q c #949494", +"r c #9c9c9c", +"s c #a5a5a5", +"t c #adadad", +"u c #b5b5b5", +"v c #bdbdbd", +"w c #c6c6c6", +"x c #cecece", +"y c #d6d6d6", +"z c #dedede", +"A c #e7e7e7", +"B c #efefef", +"C c #f7f7f7", +"D c #ff1000", +"E c #f73900", +"F c #ff7300", +"G c #efd600", +"H c #4a00ce", +"I c #7b00ff", +"J c #c600ff", +"K c #f700e7", +"L c #f700ad", +"M c #f70073", +"N c #ef0021", +"O c #000000", +/* pixels */ +"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA", +"AOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh", +"AOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh", +"AOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh", +"AOOOOOOHHIIOOOOOOOJJJJJJJKKKKOOOOOOLLLLLOOOOOOOOMMMMNNNDOOOOODDDOOOOOOEFFOOOOFFGGGGGGGGGOh", +"AOOOOOHHHIIIOOOOOOJJJOOOOOOKKKOOOOLLLOLLLOOOOOOMMMOOOONDDOOOODDDOOOOOOEFFOOOOFFGOOOOOOOOOh", +"AOOOOHHHOOIIIOOOOOJJJOOOOOOKKKOOOKLLOOOLLLOOOOOMMOOOOOOOOOOOODDDDEEEEEEFFOOOOFFGGGGGOOOOOh", +"AOOOHHHOOOOIIIOOOOJJJJJJJKKKKOOOKKLOOOOOLLMOOOOMMOOOOOOOOOOOODDDDEEEEEEFFOOOOFFGOOOOOOOOOh", +"AOOHHHHHHIIIIIJOOOJJJOOOOOOOOOOKKKLLLLLLLLMhhhhhhhOOOONDDOOOODDDOOOOOOEFFOOOOFFGOOOOOOOOOh", +"AOHHHOOOOOOOOIJJOOJJJOOOOOOOOOKKKOOOOOOOOhh.........NNNDOOOOODDDOOOOOOEFFOOOOFFGGGGGGGGGOh", +"AOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOhh..lp.........#OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh", +"AOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh...k#kOB...yauy.OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh", +"AOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh...u#nbaO...OhOql.OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh", +"AOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh...CdwBidkOC.#lez...OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOh", +"Ahhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh...movsqr.nOzijfj....hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh", +"A......................................AmwioqwByehlimi...................................h", +"A................................OO....eo.Asss.ucisqgf..............................OO...h", +"A................................OO...rmfctnsrukdyttOz..............................OO...h", +"A................................OO...hzibeeixkdbhsOu...............................OO...h", +"A.OO.OOO..OOO......OOOO......OOOOOO...rvgujfqmjdagnu...OO.OOO.......OOOO....OO.OOO..OO...h", +"A.OOO..OOO..OO....OO..OO....OO...OO....x#.wOsOs.Os.....OOO..OO.....OO..OO...OOOOOO..OO...h", +"A.OO...OO...OO...OO....OO..OO....OO....yf.Be.O#.Op.....OO....OO...OO...OO...OO......OO...h", +"A.OO...OO...OO...OO....OO..OO....OO....vm.Cl.Bi.jt.....OO....OO...OOOOOOO...OO......OO...h", +"A.OO...OO...OO...OO....OO..OO....OO....xt..xzBp.hC.....OO....OO...OO........OO......OO...h", +"A.OO...OO...OO...OO....OO..OO....OO....Cw...tv..nA.....OO....OO...OO........OO......OO...h", +"A.OO...OO...OO....OO..OO....OO..OOO....Cu..xhw..xw.....OO...OO.....OO..OO...OO......OO...h", +"A.OO...OO...OO.....OOOO......OOO.OO....xj..xzpB..u.....OOOOOO.......OOOO....OO......OO...h", +"A.......................................v........rs....OO................................h", +"A......................................................OO................................h", +"AhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhOOOOOOOOOOOOOOOOOhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh" +}; From 825544925bf16ff2d12388fc1dcdef3857fcef531f57d60238b36b598c5b3d02 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?V=C3=ADt=C4=9Bzslav=20=C4=8C=C3=AD=C5=BEek?= Date: Mon, 27 Dec 2010 11:36:41 +0000 Subject: [PATCH 2/2] Accepting request 56409 from home:vitezslav_cizek:branches:Apache:Modules OBS-URL: https://build.opensuse.org/request/show/56409 OBS-URL: https://build.opensuse.org/package/show/Apache:Modules/apache2-mod_perl?expand=0&rev=23 --- apache2-mod_perl-2.0.4-xss.patch | 47 ++++++++++++++++++++++++++++++++ apache2-mod_perl.changes | 5 ++++ apache2-mod_perl.spec | 2 ++ 3 files changed, 54 insertions(+) create mode 100644 apache2-mod_perl-2.0.4-xss.patch diff --git a/apache2-mod_perl-2.0.4-xss.patch b/apache2-mod_perl-2.0.4-xss.patch new file mode 100644 index 0000000..29a4a3d --- /dev/null +++ b/apache2-mod_perl-2.0.4-xss.patch @@ -0,0 +1,47 @@ +--- perl/modperl/trunk/lib/Apache2/Status.pm 2007/12/31 08:05:11 607697 ++++ perl/modperl/trunk/lib/Apache2/Status.pm 2009/04/01 15:39:56 760926 +@@ -29,7 +29,7 @@ use File::Spec (); + + use Apache2::Const -compile => qw(OK); + +-$Apache2::Status::VERSION = '4.00'; # mod_perl 2.0 ++$Apache2::Status::VERSION = '4.01'; # mod_perl 2.0 + + use constant IS_WIN32 => ($^O eq "MSWin32"); + +@@ -126,7 +126,7 @@ sub handler { + $r->print(symdump($r, $qs)); + } + else { +- my $uri = $r->uri; ++ my $uri = $r->location; + $r->print('

'); + $r->print( + map { qq[$status{$_}
\n] } sort { lc $a cmp lc $b } keys %status +@@ -198,7 +198,7 @@ sub status_section_config { + sub status_inc { + my ($r) = @_; + +- my $uri = $r->uri; ++ my $uri = $r->location; + my @retval = ( + '', + "", +@@ -289,7 +289,7 @@ sub status_rgysubs { + my ($r) = @_; + + local $_; +- my $uri = $r->uri; ++ my $uri = $r->location; + my $cache = __PACKAGE__->registry_cache; + + my @retval = "

Compiled registry scripts grouped by their handler

"; +@@ -765,7 +765,7 @@ sub as_HTML { + my ($self, $package, $r) = @_; + + my @m = qw(
); +- my $uri = $r->uri; ++ my $uri = $r->location; + my $is_main = $package eq "main"; + + my $do_dump = has($r, "dumper"); diff --git a/apache2-mod_perl.changes b/apache2-mod_perl.changes index 107cfdb..d7d59ef 100644 --- a/apache2-mod_perl.changes +++ b/apache2-mod_perl.changes @@ -1,3 +1,8 @@ +------------------------------------------------------------------- +Mon Dec 20 11:35:31 UTC 2010 - vcizek@novell.com + +- bnc#495434 (cve-2009-0796) + ------------------------------------------------------------------- Thu Nov 25 18:09:09 UTC 2010 - chris@computersalat.de diff --git a/apache2-mod_perl.spec b/apache2-mod_perl.spec index d04e238..1c6aad2 100644 --- a/apache2-mod_perl.spec +++ b/apache2-mod_perl.spec @@ -46,6 +46,7 @@ Version: 2.0.4 Release: 48 Source0: mod_perl-%{version}.tar.bz2 Patch: %{name}-%{version}-tests.diff +Patch1: apache2-mod_perl-2.0.4-xss.patch #%define apache_test_version 1_99_15 # cvs -d :pserver:anoncvs@cvs.apache.org:/home/cvspublic up -r MODPERL_%{apache_test_version} #Source1: Apache-Test-%{apache_test_version}.tar.bz2 @@ -108,6 +109,7 @@ software depending on apache2-mod_perl. #%setup -q -n modperl-2.0 -a 1 %setup -q -n mod_perl-%{version} %patch +%patch1 -p3 find -name ".svn" -type d | xargs rm -rfv %build