Mantis - Resin
Viewing Issue Advanced Details
4744 minor always 09-01-11 13:31 09-06-11 13:42
cowan  
 
normal  
closed  
fixed  
none    
none 4.0.23  
0004744: Range header handling
CVE-2011-3192

http://seclists.org/fulldisclosure/2011/Aug/175 [^]

And the relevant Apache advisory:
https://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3C20110824161640.122D387DD@minotaur.apache.org%3E [^]
Rep by R. Madej

Notes
(0005491)
ferg   
09-06-11 13:42   
The exact Apache resource issue doesn't apply to Resin, but added Range limit checking to the file servlet and caching to avoid possibility of extending a large file to a larger file.