summaryrefslogtreecommitdiff
path: root/Python/ceval.c
diff options
context:
space:
mode:
authorSenthil Kumaran <senthil@uthcode.com>2016-07-30 23:24:16 -0700
committerSenthil Kumaran <senthil@uthcode.com>2016-07-30 23:24:16 -0700
commit4cbb23f8f278fd1f71dcd5968aa0b3f0b4f3bd5d (patch)
tree6b9afcfb2dbbcaba109a7b00785f711af576c538 /Python/ceval.c
parentd27a7c1f22b263a3eef5d380c7058c993bd3a451 (diff)
downloadcpython-git-4cbb23f8f278fd1f71dcd5968aa0b3f0b4f3bd5d.tar.gz
Prevent HTTPoxy attack (CVE-2016-1000110)
Ignore the HTTP_PROXY variable when REQUEST_METHOD environment is set, which indicates that the script is in CGI mode. Issue #27568 Reported and patch contributed by Rémi Rampin.
Diffstat (limited to 'Python/ceval.c')
0 files changed, 0 insertions, 0 deletions