Bug#792423: apache2.2-bin: Segfault at timeout with a no-output CGI

2015-07-14 Thread Simone Piccardi
Package: apache2.2-bin
Version: 2.2.22-13+deb7u4
Severity: normal

Dear Maintainer,

I got this problem because blocked CGI were not killed after timout
and instead I got in the error log something like:


[Tue Jul 14 17:16:30 2015] [notice] child pid 11032 exit signal Segmentation 
fault (11)

I can reproduce this one creating a doing nothing CGI like this one:

http://gapil.truelite.it/sources/browser/trunk/sources/testsignalcgi.c

installing in /usr/lib/cgi-bin and asking it with a browser. At the
timout the result is a segfault in the apache child that launched the
CGI, before it can send the SIGTERM to the CGI.

This behaviour disappear if I remove mod_deflate and restart apache. 

I already got this bug in Lenny (only for 64 bit platform), but it's
not present in Squeeze. I cannot test it in a 32 bit machine (that I
don't have).

Regards
Simone

-- System Information:
Debian Release: 7.8
  APT prefers oldstable-updates
  APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.32-34-pve (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/dash

Versions of packages apache2.2-bin depends on:
ii  libapr1  1.4.6-3+deb7u1
ii  libaprutil1  1.4.1-3
ii  libaprutil1-dbd-sqlite3  1.4.1-3
ii  libaprutil1-ldap 1.4.1-3
ii  libc62.13-38+deb7u8
ii  libcap2  1:2.22-1.2
ii  libldap-2.4-22.4.31-2
ii  libpcre3 1:8.30-5
ii  libssl1.0.0  1.0.1e-2+deb7u17
ii  zlib1g   1:1.2.7.dfsg-13

apache2.2-bin recommends no packages.

apache2.2-bin suggests no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/20150714165125.14736.94067.report...@holland.truelite.it



Bug#792423: apache2.2-bin: Segfault at timeout with a no-output CGI

2015-07-14 Thread Abraham López Ameneyro
remove


*Abraham López | WebIT Marketing*
*CEO  CTO*

2015-07-14 11:51 GMT-05:00 Simone Piccardi picca...@truelite.it:

 Package: apache2.2-bin
 Version: 2.2.22-13+deb7u4
 Severity: normal

 Dear Maintainer,

 I got this problem because blocked CGI were not killed after timout
 and instead I got in the error log something like:


 [Tue Jul 14 17:16:30 2015] [notice] child pid 11032 exit signal
 Segmentation fault (11)

 I can reproduce this one creating a doing nothing CGI like this one:

 http://gapil.truelite.it/sources/browser/trunk/sources/testsignalcgi.c

 installing in /usr/lib/cgi-bin and asking it with a browser. At the
 timout the result is a segfault in the apache child that launched the
 CGI, before it can send the SIGTERM to the CGI.

 This behaviour disappear if I remove mod_deflate and restart apache.

 I already got this bug in Lenny (only for 64 bit platform), but it's
 not present in Squeeze. I cannot test it in a 32 bit machine (that I
 don't have).

 Regards
 Simone

 -- System Information:
 Debian Release: 7.8
   APT prefers oldstable-updates
   APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
 Architecture: amd64 (x86_64)

 Kernel: Linux 2.6.32-34-pve (SMP w/1 CPU core)
 Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
 Shell: /bin/sh linked to /bin/dash

 Versions of packages apache2.2-bin depends on:
 ii  libapr1  1.4.6-3+deb7u1
 ii  libaprutil1  1.4.1-3
 ii  libaprutil1-dbd-sqlite3  1.4.1-3
 ii  libaprutil1-ldap 1.4.1-3
 ii  libc62.13-38+deb7u8
 ii  libcap2  1:2.22-1.2
 ii  libldap-2.4-22.4.31-2
 ii  libpcre3 1:8.30-5
 ii  libssl1.0.0  1.0.1e-2+deb7u17
 ii  zlib1g   1:1.2.7.dfsg-13

 apache2.2-bin recommends no packages.

 apache2.2-bin suggests no packages.

 -- no debconf information