Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 19 Jun 2002 17:39:02 +0300
From:      Maxim Sobolev <sobomax@FreeBSD.org>
To:        "Jacques A. Vidrine" <nectar@FreeBSD.org>
Cc:        security@FreeBSD.org, Alexandr Kovalenko <never@nevermind.kiev.ua>, demon@FreeBSD.org, lev@serebryakov.spb.ru
Subject:   Re: [Fwd: Russian Apache is not vulnerable to recent DoS]
Message-ID:  <3D109786.F6CC57B7@FreeBSD.org>
References:  <3D1079D3.2BCF833F@FreeBSD.org> <20020619135156.GA19379@madman.nectar.cc>

next in thread | previous in thread | raw e-mail | index | archive | help
"Jacques A. Vidrine" wrote:
> 
> On Wed, Jun 19, 2002 at 03:32:19PM +0300, Maxim Sobolev wrote:
> > Redirect to a proper place.
> 
> Thanks, Maxim!
> 
> > -------- Original Message --------
> > Subject: Russian Apache is not vulnerable to recent DoS
> > Date: Wed, 19 Jun 2002 15:01:11 +0300
> > From: Alexandr Kovalenko <never@nevermind.kiev.ua>
> > To: freebsd-ports@FreeBSD.org
> >
> > Russian Apache is not vulnerable to recent apache vulnerability,
> > because
> > it does not use code, which causes it. Please, remove FORBIDDEN from
> > russian/apach13 and russian/apache13-ssl.
> 
> Do you a pointer to an analysis that leads to this conclusion?

Some information is available here:
http://www.lucky.net/~netch/tmp/apache-chunking-bugtraq.txt.

-Maxim

> 
> If the maintainers are convinced, then they can remove FORBIDDEN.
> I'm cc:ing them so that they are in the loop.
> 
> Cheers,
> --
> Jacques A. Vidrine <n@nectar.cc>                 http://www.nectar.cc/
> NTT/Verio SME          .     FreeBSD UNIX     .       Heimdal Kerberos
> jvidrine@verio.net     .  nectar@FreeBSD.org  .          nectar@kth.se

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3D109786.F6CC57B7>