Contributed by jose on from the leaks-get-stopped dept.
httpd(8) leaks file inode numbers via ETag header as well as child PIDs in multipart MIME boundary generation. This could lead, for example, to NFS exploitation because it uses inode numbers as part of the file handle.Patch 008 for 3.2 has been released to fix these problems. Users of -current will already have the patch applied. Thanks to Chad Loder for the heads up.
(Comments are closed)