Submitted by: Eric Covener <covener gmail.com>
Reviewed by: trawick
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@201455
13f79535-47bb-0310-9956-
ffa450edef68
Changes with Apache 2.1.6
[Remove entries to the current 2.0 section below, when backported]
+ *) Fix htdbm password validation for records which included comments.
+ [Eric Covener <covener gmail.com>]
+
*) SECURITY:
proxy HTTP: If a response contains both Transfer-Encoding and a
Content-Length, remove the Content-Length and don't reuse the
if (apr_dbm_fetch(htdbm->dbm, key, &val) != APR_SUCCESS)
return APR_ENOENT;
rec = apr_pstrndup(htdbm->pool, val.dptr, val.dsize);
- cmnt = strchr(rec, ';');
+ cmnt = strchr(rec, ':');
if (cmnt)
strncpy(pwd, rec, cmnt - rec);
else