|
Re: lug-bg: I pak za apache
- Subject: Re: lug-bg: I pak za apache
- From: danchev@xxxxxxxxx (George Danchev)
- Date: Mon, 24 Jun 2002 11:37:19 +0300
On Monday 24 June 2002 10:48, Iassen Anadoliev wrote:
> Sorry che pak wrushtam temata za apache. Pri nqkogo polu4awal li se e
> slednoto neshto: Connectwate se prashtate request-a i connection-a nito
> dropi, nito kazwa bad request. Samo deto Apache-a po4wa da qde cpu-to na
> max Apache 1.3.19 running on FreeBSD.
òîâà ïðèëè÷à íà îïèñàíîòî â advisory-òî
In most cases the outcome of the invalid request is that the child process
dealing with the request will terminate. At the least, this could help a
remote attacker launch a denial of service attack as the parent process
will eventually have to replace the terminated child process, and starting
new children uses non-trivial amounts of resources.
íå âèæäàì êàêâî èìà äà ñå óìóâà òîëêîâà, ñëåä êàòî ñå ïîäîçèðà âñåêè
àïàõ < 1.3.16 èëè 2.0.39. Àêî äúðæèø íà òâîÿò 1.3.19 ïðèëàãàø
http://www.apache.org/dist/httpd/patches/apply_to_1.3.22/SECURITY_chunk_size_patch.txt
èëè cvsup íà ports-www (èëè íà öåëèÿ Ports ÷å ïî safe) & recompile ....
--
Greets,
fr33zb1
============================================================================
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
============================================================================
|
|
|