Bug#873115: Acknowledgement (concurrent apache2 -k graceful hang)

2017-08-24 Thread Joey Hess
Seems similar to #779077. mod_fcgid is not enabled on our server. Regular cgi scripts are in use and one is quite likely running when apache is reloaded. Using mpm_worker. -- see shy jo signature.asc Description: PGP signature

Bug#873115: concurrent apache2 -k graceful hang

2017-08-24 Thread Joey Hess
Package: apache2 Version: 2.4.25-3+deb Severity: normal I woke up to a server with hundreds of apach2e -k graceful processes running. This prevented any cgis from running since it was nearly out of process slots. 2142 ?SNs0:01 /usr/sbin/apache2 -k graceful 6007 ?SN 0:00

Re: Bug#742145: openssl: uses only 32 bytes (256 bit) for key generation

2014-03-19 Thread Joey Hess
Thorsten Glaser wrote: Florian Weimer dixit: Historically, the OpenSSL command line tools have been intended for debugging only. I disagree, in the case of genrsa and friends anyway. Me too, and openssl(1ssl) does not mention debugging or not for production use or give any warnings. Also,

Re: Bug#742145: openssl: uses only 32 bytes (256 bit) for key generation

2014-03-19 Thread Joey Hess
The amount of seed material required to generate a cryptographic key equals the effective key size of the key. For example, a 3072-bit RSA or Diffie-Hellman private key has an effective key size of 128 bits (it requires about 2^128 operations to break) so a key

Bug#711121: bug script is buggy

2013-06-04 Thread Joey Hess
Package: apache2 Version: 2.4.4-5 Severity: normal Running reportbug apache2 results in a lot of: Unsuccessful stat on filename containing newline at /usr/share/bug/apache2/script line 44. Unsuccessful stat on filename containing newline at /usr/share/bug/apache2/script line 44. Unsuccessful

Bug#711120: init script is silent

2013-06-04 Thread Joey Hess
Package: apache2 Version: 2.4.4-5 Severity: normal The init script no longer outputs anything when starting or stopping the daemon. This is rather disconcerting when one is trying to restart apache to deal with massive changes to the configuration system. (It's also probably a policy violation.)

Bug#707770: sosospider+gitweb caused apache memory use to balloon and not go back down

2013-05-11 Thread Joey Hess
Package: apache2.2-common Version: 2.2.22-13 Severity: normal See attached graph.png. The 1+ gb memory plateau is due to apache, which should normally be using more like 10 mb. I noticed this, and restarted it. A few hours later it happened again. At that point, I was using mpm-worker; I

Bug#576089: empty /usr/lib/debug/usr/sbin

2010-03-31 Thread Joey Hess
Package: apache2-mpm-worker Version: 2.2.15-2 Severity: minor The package contains an empty /usr/lib/debug/usr/sbin, which seems to have no purpose. -- Package-specific info: List of enabled modules from 'apache2 -M': alias auth_basic authn_file authz_default authz_groupfile authz_host

Bug#357561: privilege escalation hole

2007-02-28 Thread Joey Hess
Daniel Leidert wrote: Why isn't anybody of the official maintainers reacting or commenting on this bug? There are 3(!) completely undocumented downgrades of a bug, # holes depending on terminal exploits have not been treated as RC I suspect that the above downgrade message from vorlon is the

Bug#393277: /etc/apache2/sites-available/default contains ubuntu non-sequitor

2006-10-15 Thread Joey Hess
Package: apache2.2-common Version: 2.2.3-2 Severity: normal # Commented out for Ubuntu #RedirectMatch ^/$ /apache2-default/ Last I checked, I do not use Ubuntu, so this is very strange. -- System Information: Debian Release: testing/unstable APT prefers

Bug#331741: apache2 depends on debconf without | debconf-2.0 alternate; blocks cdebconf transition

2005-10-04 Thread Joey Hess
Package: apache2 This package depends/pre-depends on debconf without allowing the dependency to be satisfied with an alternate of debconf-2.0. That is to say, its dependency should read: debconf | debconf-2.0 Until this is fixed, it is impossible to use this package with cdebconf, and very hard

Bug#322604: SECURITY: Vulnerable to CAN-2005-1344?

2005-08-11 Thread Joey Hess
notfound 322604 2.0.54-3 merge 307134 322604 thanks Christian Hammers wrote: Hello Apache maintainers, please check if Debian is vulnerable to CAN-2005-1344 and make sure it enters http://www.debian.org/security/crossreferences or the not-vulnerable lists. You can find a note that this bug

Bug#307134: CAN-2005-1344 htdigest buffer overflow

2005-04-30 Thread Joey Hess
Package: apache2 Severity: normal Tags: security I've verified that the htdigest from apache2 has the buffer overflow described at http://www.lucaercoli.it/advs/htdigest.txt I dont know of any exploit vectors, as noted it doiesn't work unless something passes user-supplied parameters to htdigest

Bug#264070: does not install a default index.html

2004-08-06 Thread Joey Hess
Package: apache2-common Version: 2.0.49-1 Severity: normal Machines with apache2 freshly installed via the web server task have a front page that looks like this: Index of / Icon NameLast modified Size Description

Bug#264106: conf.d and sites-enabled cannot be checked into svn

2004-08-06 Thread Joey Hess
Package: apache2-common Version: 2.0.49-1 Severity: wishlist Apparently apache looks inside dot-directories of the conf.d and sites-enabled directories, which means I cannot check them into svn with the rest of my apache configuration. [EMAIL PROTECTED]:/var/etc/init.d/apache2 start Starting web

Bug#255974: fwiw

2004-06-26 Thread Joey Hess
I can reproduce the problem with the documentroot. -- see shy jo signature.asc Description: Digital signature

Bug#230485: apache2/ssl-cert's debconf abuse makes baby jesus cry

2004-01-30 Thread Joey Hess
Package: ssl-cert Severity: normal Read and weep: Configuration file `/etc/init.d/apache2' == File on system created by you or by a script. == File also in package provided by package maintainer. What would you like to do about it ? Your options are: Y or I : install the package

Bug#227653: suexec is on by default, breaks user cgi scripts if UserDir has changed

2004-01-13 Thread Joey Hess
Package: apache2-common Version: 2.0.48-4 Severity: normal Read this strace and weep: stat64(/home/joey/html/blog/index.cgi, {st_mode=S_IFREG|0755, st_size=1538, ...}) = 0 .. fork(Process 3822 attached .. [pid 3822] execve(/usr/lib/apache2/suexec2, [/usr/lib/apache2/suexec2, ~1000, 1000,