in /subdir. All CVE-2009-1195 tests still pass with this patch.
# only two containers in the config
<Directory />
Options Includes
AllowOverride None
</Directory>
<Directory /subdir>
# with this container, mod_cgi/mod_cgid complains about exec being off
# without it, exec cmd= works as expected
SetEnv foo bar
</Directory>
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@773322
13f79535-47bb-0310-9956-
ffa450edef68
/* if Includes was enabled without exec in the new config, but
* was enabled with exec in the base, then disable exec in the
* resulting options. */
- if ((base->opts & OPT_INC_WITH_EXEC)
- && (new->opts & OPT_INC_WITH_EXEC) == 0) {
+ if ((base->opts & OPT_INC_WITH_EXEC)
+ && (new->opts & OPT_INC_WITH_EXEC) == 0
+ && (new->opts & OPT_INCLUDES)) {
conf->opts &= ~OPT_INC_WITH_EXEC;
}
}