httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Rasmus Lerdorf <ras...@apache.org>
Subject Re: [users@httpd] ** New Apache vulnerability ?? *** Apache HTTP Server MIME message boundaries information disclosure
Date Tue, 08 Apr 2003 08:34:48 GMT
Why don't you just follow the remedy instructions given right at the URL
you referenced.  Either disable FileEtag or apply the patch they
reference:

  ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/008_httpd.patch

But yes, this should probably be addressed in the main Apache code base.  
This patch, or one like it, is not in CVS yet.

-Rasmus

On Tue, 8 Apr 2003, Hassan S wrote:

> [ 2nd try]
> 
> Any response is highly appreciated.
> 
> Thanks
> Hassan
> 
> --- Hassan S <sunishu@yahoo.com> wrote:
> > Hello Everyone,
> > 
> > Did anyone remedy this vulnerability which was
> > described in the following link?
> > 
> > http://www.iss.net/security_center/static/11438.php
> > 
> > What are the necessary steps (patch, if any) to
> > take?
> > 
> > Thanks in advance,
> > Hasan
> > 
> > __________________________________________________
> > Do you Yahoo!?
> > Yahoo! Tax Center - File online, calculators, forms,
> > and more
> > http://tax.yahoo.com
> > 
> >
> ---------------------------------------------------------------------
> > The official User-To-User support forum of the
> > Apache HTTP Server Project.
> > See <URL:http://httpd.apache.org/userslist.html> for
> > more info.
> > To unsubscribe, e-mail:
> > users-unsubscribe@httpd.apache.org
> >    "   from the digest:
> > users-digest-unsubscribe@httpd.apache.org
> > For additional commands, e-mail:
> > users-help@httpd.apache.org
> > 
> 
> 
> __________________________________________________
> Do you Yahoo!?
> Yahoo! Tax Center - File online, calculators, forms, and more
> http://tax.yahoo.com
> 
> ---------------------------------------------------------------------
> The official User-To-User support forum of the Apache HTTP Server Project.
> See <URL:http://httpd.apache.org/userslist.html> for more info.
> To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
>    "   from the digest: users-digest-unsubscribe@httpd.apache.org
> For additional commands, e-mail: users-help@httpd.apache.org
> 



---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


Mime
View raw message