Contributed by jose on from the leaks-get-stopped dept.
httpd(8) leaks file inode numbers via ETag header as well as child PIDs in multipart MIME boundary generation. This could lead, for example, to NFS exploitation because it uses inode numbers as part of the file handle.Patch 008 for 3.2 has been released to fix these problems. Users of -current will already have the patch applied. Thanks to Chad Loder for the heads up.
(Comments are closed)
By Anonymous Coward () on
By Anonymous Coward () on
===> src
===> src/os/unix
src/ap
make: don't know how to make ap_strtol.c. Stop in /usr/src/usr.sbin/httpd/obj/src/ap.
*** Error code 1
Stop in /usr/src/usr.sbin/httpd/obj/src (line 154 of Makefile).
*** Error code 1
Stop in /usr/src/usr.sbin/httpd/obj (line 202 of ./Makefile).
*** Error code 1
Stop in /usr/src/usr.sbin/httpd/obj (line 184 of Makefile).
*** Error code 1
Stop in /usr/src/usr.sbin/httpd (line 789 of /usr/src/usr.sbin/httpd/Makefile.bsd-wrapper).
By Apache 1.3.26? () on
is it just me or have i not seen these bugs fixed in openbsd
By WWW () on