Received: (from majordom@localhost) by hyperreal.com (8.8.5/8.8.5) id XAA25657; Sun, 22 Jun 1997 23:33:04 -0700 (PDT) Received: from plato.alameda-coe.k12.ca.us (plato.alameda-coe.k12.ca.us [206.110.1.34]) by hyperreal.com (8.8.5/8.8.5) with SMTP id XAA25653 for ; Sun, 22 Jun 1997 23:33:02 -0700 (PDT) Received: from pappilloma.wwebsvs.com by plato.alameda-coe.k12.ca.us with smtp (Smail3.1.29.1 #5) id m0wg2Wu-000OYkC; Sun, 22 Jun 97 23:23 PDT Received: from ace.nueva.pvt.k12.ca.us by pappilloma.wwebsvs.com (SMI-8.6/SMI-SVR4) id WAA13005; Sun, 22 Jun 1997 22:28:21 -0700 Received: from localhost by ace.nueva.pvt.k12.ca.us with SMTP (1.37.109.20/15.5+ECS 3.3+HPL1.1) id AA248117577; Sun, 22 Jun 1997 23:32:57 -0700 Date: Sun, 22 Jun 1997 23:32:57 -0700 (PDT) From: Alexei Kosut To: new-httpd@apache.org Subject: Re: [PATCH] various security problems In-Reply-To: <199706230600.BAA08008@sierra.zyzzyva.com> Message-Id: Mime-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: new-httpd-owner@apache.org Precedence: bulk Reply-To: new-httpd@apache.org On Mon, 23 Jun 1997, Randy Terbush wrote: > *sigh* I was hoping this email had been my imagination... > > This sounds pretty serious, and by virtue of it being posted on > this list, I think we had better move quickly to release a 1.2.1. If we are going to release a 1.2.1, I think we need to ensure that we put all the bug fixes out there into it. These include most of the patches put into HEAD in the last few days, as well as some others. Dean was keeping a list, I think. Some of those patches have been committed, some haven't. I don't think any have been committed to the 1.2 branch, only the head. > Are these problems worth creating a vendor initiated CERT advisory? I don't think so. Most of these problems are, to my thinking, essentially configuration issues. There is nothing that someone on the outside of the web server could really do to take advantage of these on most sites, but they could cause the web server admin to accidentally enable the server to do things he might not have intended, especially if the server is being used to serve pages of untrusted users. -- ________________________________________________________________________ Alexei Kosut The Apache HTTP Server URL: http://www.nueva.pvt.k12.ca.us/~akosut/ http://www.apache.org/