[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Bug: committers can set arbitrary HTTP Headers on any file

From: Brian W. Fitzpatrick <fitz_at_red-bean.com>
Date: 2007-08-11 05:40:48 CEST

On 8/10/07, David Glasser <glasser@davidglasser.net> wrote:
> On 8/10/07, Brian W. Fitzpatrick <fitz@red-bean.com> wrote:
> > Summary: by providing a multi-line value for the svn:mime-type
> > property, you can add arbitrary headers to any mod_dav_svn response
> > for a file in a Subversion repository
>
> Should we also report this to Apache HTTPD as a bug in ap_set_content_type?

What should the behavior be if it gets a multiline value? I'm inclined
to just own this one...

-Fitz

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Received on Sat Aug 11 05:38:51 2007

This is an archived mail posted to the Subversion Dev mailing list.