apache2-devel: Apache 2.0 Header and Include Files ---------------------------------------------------------------------- File: apache2-devel-2.2.3-26.ppc.rpm Patchrpm: apache2-devel-2.2.3-26.ppc.patch.rpm Version: 2.2.3-26 Size: 208 kB Patchsize: 110 kB Date: Thu 25 Sep 2008 13:40:36 CEST Source: apache2-2.2.3-26.src.rpm Security: Yes ---------------------------------------------------------------------- Description: Missing sanity checks of FTP URLs allowed cross site scripting (XSS) attacks via the mod_proxy_ftp module (CVE-2008-2939). Missing precautions allowed cross site request forgery (CSRF) via the mod_proxy_balancer interface (CVE-2007-6420).