commit | 436fe5a447abb69e5e5a4f453325c422af02dcaa | [log] [tgz] |
---|---|---|
author | Senthil Kumaran <senthil@uthcode.com> | Sat Jul 30 23:34:34 2016 -0700 |
committer | Senthil Kumaran <senthil@uthcode.com> | Sat Jul 30 23:34:34 2016 -0700 |
tree | 6087c6640f2e39e4e8bd1e7b7b6490e8e0b7f324 | |
parent | b7b5d35545d2d078e868cbda485bc4651edec4ff [diff] | |
parent | 4cbb23f8f278fd1f71dcd5968aa0b3f0b4f3bd5d [diff] |
[merge from 3.3] Prevent HTTPoxy attack (CVE-2016-1000110) Ignore the HTTP_PROXY variable when REQUEST_METHOD environment is set, which indicates that the script is in CGI mode. Issue #27568 Reported and patch contributed by RĂ©mi Rampin.