via malicious backend servers (CVE-2026-34356) Resolves: RHEL-186190 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) Resolves: RHEL-186181 - httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) Resolves: RHEL-186160 - httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) Resolves: RHEL-184308 - httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) Resolves : RHEL-182579 - httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) Resolves: RHEL-175622 - httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) Resolves: RHEL-193112 - httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) Resolves: RHEL-234657 - httpd: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072) Resolves: RHEL-191241 - httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951) Also addresses CVE-2026-44119, CVE-2026-42535, CVE-2026-33006
17 lines
812 B
Diff
17 lines
812 B
Diff
diff --git a/modules/http/http_filters.c b/modules/http/http_filters.c
|
|
index 732fb8e..ef24122 100644
|
|
--- a/modules/http/http_filters.c
|
|
+++ b/modules/http/http_filters.c
|
|
@@ -1381,10 +1381,10 @@ static void merge_response_headers(request_rec *r, const char **protocol)
|
|
if (!apr_is_empty_array(r->content_languages)) {
|
|
int i;
|
|
char *token;
|
|
- char **languages = (char **)(r->content_languages->elts);
|
|
const char *field = apr_table_get(r->headers_out, "Content-Language");
|
|
|
|
while (field && (token = ap_get_list_item(r->pool, &field)) != NULL) {
|
|
+ char **languages = (char **)(r->content_languages->elts);
|
|
for (i = 0; i < r->content_languages->nelts; ++i) {
|
|
if (!ap_cstr_casecmp(token, languages[i]))
|
|
break;
|