From 9b558064400e1267cd4da011371c818a6792b9b4 Mon Sep 17 00:00:00 2001 From: radek Date: Fri, 23 Mar 2007 13:03:59 +0000 Subject: [PATCH] - fix path_info related security issue Changed files: apache-mod_perl-path_info_secfix.patch -> 1.1 --- apache-mod_perl-path_info_secfix.patch | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 apache-mod_perl-path_info_secfix.patch diff --git a/apache-mod_perl-path_info_secfix.patch b/apache-mod_perl-path_info_secfix.patch new file mode 100644 index 0000000..fc64dd6 --- /dev/null +++ b/apache-mod_perl-path_info_secfix.patch @@ -0,0 +1,11 @@ +--- ModPerl-Registry/lib/ModPerl/RegistryCooker.pm~ 2006-11-20 00:31:41.000000000 +0100 ++++ ModPerl-Registry/lib/ModPerl/RegistryCooker.pm 2007-03-23 14:01:52.606187672 +0100 +@@ -337,7 +337,7 @@ + my $self = shift; + + my $path_info = $self->{REQ}->path_info; +- my $script_name = $path_info && $self->{URI} =~ /$path_info$/ ++ my $script_name = $path_info && $self->{URI} =~ /\Q$path_info\E$/ + ? substr($self->{URI}, 0, length($self->{URI}) - length($path_info)) + : $self->{URI}; + -- 2.44.0