diff --git a/debian/changelog b/debian/changelog index c0254206d4b077af3d0dc18a54be78b28bef4832..fac177db0d2d6986fe8bc27c361c6875b3c72973 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,9 @@ +apache2 (2.4.54-ok3) yangtze; urgency=medium + + * dong-hantao CVE-2022-36760 安全更新:Apache HTTP Server 环境问题漏洞. + + -- donghantao Thu, 09 Mar 2023 11:11:51 +0800 + apache2 (2.4.54-ok2) yangtze; urgency=medium * mrmoney1 CVE-2006-20001 安全更新:Apache HTTP Sever一些版本的缓冲区错误漏洞. diff --git a/modules/proxy/mod_proxy_ajp.c b/modules/proxy/mod_proxy_ajp.c index 226ad9b3de3acf09dae50d9538e628fab0cabf08..1449acad7334b90dbbe46500ec57095928f4994c 100644 --- a/modules/proxy/mod_proxy_ajp.c +++ b/modules/proxy/mod_proxy_ajp.c @@ -257,6 +257,8 @@ static int ap_proxy_ajp_request(apr_pool_t *p, request_rec *r, ap_log_rerror(APLOG_MARK, APLOG_ERR, 0, r, APLOGNO(10396) "%s Transfer-Encoding is not supported", tenc); + /* We had a failure: Close connection to backend */ + conn->close = 1; return HTTP_INTERNAL_SERVER_ERROR; } } else {