httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Randy Terbush <>
Subject Re: Agenda for 1.2b7
Date Wed, 29 Jan 1997 16:43:51 GMT

> On Wed, 29 Jan 1997, Marc Slemko wrote:
> >   * suexec sets environ to local variable, possibly to overwrite
> >     memory by too many environ variables
> > 
> > 	status: Jason looking at it
> 	Fix is simple, I believe, and I will have a patch soon.  This will
> also need to be patched in the server for safety since we pulled the code
> directly from there...

clean_env() did _not_ come from the server. I just forgot to add
the check for the allocated limit of slots. As I think about this,
it might also be good form to calloc that array of pointers.

View raw message