httpd-bugs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject DO NOT REPLY [Bug 33765] - htdigest creates digest files suid/sgid
Date Mon, 28 Feb 2005 12:08:25 GMT
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG·
RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT
<http://issues.apache.org/bugzilla/show_bug.cgi?id=33765>.
ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND·
INSERTED IN THE BUG DATABASE.

http://issues.apache.org/bugzilla/show_bug.cgi?id=33765





------- Additional Comments From chris+apache@chrullrich.de  2005-02-28 13:08 -------
(In reply to comment #1)
> Hmm, I'd guess your APR headers are outdated (i.e. not matching the lib
> version). Could this be?

I don't think so. One, I installed the whole thing from the FreeBSD ports
collection, and the APR headers are in the same package as the server, and two,
the bug doesn't have anything to do with a wrong #define. In support/htdigest.c,
even in HEAD, there is a call to apr_file_open() with -1 as fourth argument. Not
something that's #defined to -1, but a literal -1.

APR_OS_DEFAULT (what htpasswd uses instead) is 07777, but it's special-cased in
libapr to use 00666.

-- 
Configure bugmail: http://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

---------------------------------------------------------------------
To unsubscribe, e-mail: bugs-unsubscribe@httpd.apache.org
For additional commands, e-mail: bugs-help@httpd.apache.org


Mime
View raw message