angler-fishThe Vulnerability History Project

SECURITY: CVE-2017-3169 (cve.mitre.org)

      mod_ssl may dereference a NULL pointer when third-party modules call
ap_hook_process_connection() during an HTTP request to an HTTPS port.

Merge r1796343 from trunk:

mod_ssl: fix ctx passed to ssl_io_filter_error()

Consistently pass the expected bio_filter_in_ctx_t
to ssl_io_filter_error(). 

Submitted by: ylavic, covener
Reviewed by: covener, ylavic, jim


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1796854 13f79535-47bb-0310-9956-ffa450edef68
    
commit a0403e8220676ecc1272bb02b0aa99e8992b8ec9
-3
+6
+7 -8
expand_less