Bug#279753: marked as done (apache: execute arbitrary code via SSI issue (CAN-2004-0940))

2004-11-05 Thread Debian Bug Tracking System
Your message dated Fri, 05 Nov 2004 08:33:14 +0100 with message-id [EMAIL PROTECTED] and subject line Bug#279753: apache: execute arbitrary code via SSI issue (CAN-2004-0940) has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt

Bug#279753: apache: execute arbitrary code via SSI issue (CAN-2004-0940)

2004-11-05 Thread Fabio Massimo Di Nitto
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hideki Yamane wrote: | Hi, | | | Yes, stability is most important thing in stable release. | | I would ask you that it needs to be built on all woody arch means | it needs more time to be checked because changed source should be | able to be built

Re: Bug#279753: apache: execute arbitrary code via SSI issue (CAN-2004-0940)

2004-11-05 Thread Fabio Massimo Di Nitto
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 This is offtopic for the bug. Hideki Yamane wrote: | Hi, | | Fri, 05 Nov 2004 09:32:59 +0100, Fabio Massimo Di Nitto | Re: Bug#279753: apache: execute arbitrary code via SSI issue (CAN-2004-0940) | | Is that review process on public or closed?

Bug#279753: apache: execute arbitrary code via SSI issue (CAN-2004-0940)

2004-11-05 Thread Hideki Yamane
Hi, Fri, 05 Nov 2004 09:32:59 +0100, Fabio Massimo Di Nitto Re: Bug#279753: apache: execute arbitrary code via SSI issue (CAN-2004-0940) Is that review process on public or closed? If it is on public, where can we read about that? a combination of all of them :-) the source needs

Bug#237377: unsure if I am suffering the same tihng

2004-11-05 Thread Jon Dowland
I am not sure if what I am suffering is due to the same bug. Firstly, if this is a known problem, I have only been experiencing it since Oct 25. It is not intermittent for me and happens consistently at night. I believe this is due to logrotation, it appears at least that apache dies at roughly

bug in debian apache?

2004-11-05 Thread Peter Bredlöv
Hi! I just upgraded to the newest (-7) release. But now i can't start apache again, and i get this error in my error log: [Tue Nov 2 00:36:40 2004] [warn] make_sock: problem listening on port 80, filedescriptor (1069) larger than FD_SETSIZE (1024) found, you probably need to rebuild Apache

Bug#279865: apache-common: CAN-2004-0940 Vulnerable?

2004-11-05 Thread Helge Kreutzmann
Package: apache-common Version: 1.3.26-0woody5 Severity: grave Justification: user security hole Tags: woody, security According to http://www.apache.org/dist/httpd/Announcement.html the new apache fixes two vulnerabilities with CAN-numbers. While -492 was fixed in a previous security upload,

Bug#279865: marked as done (apache-common: CAN-2004-0940 Vulnerable?)

2004-11-05 Thread Debian Bug Tracking System
Your message dated Fri, 05 Nov 2004 15:03:33 +0100 with message-id [EMAIL PROTECTED] and subject line Bug#279865: apache-common: CAN-2004-0940 Vulnerable? has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the

Bug#237377: unsure if I am suffering the same tihng

2004-11-05 Thread Dave Ewart
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Friday, 05.11.2004 at 11:46 +, Jon Dowland wrote: I am not sure if what I am suffering is due to the same bug. Firstly, if this is a known problem, I have only been experiencing it since Oct 25. It is not intermittent for me and

Bug#279875: removing apache2-mpm-worker fails

2004-11-05 Thread Herbert Thielen
Package: apache2-mpm-worker Version: 2.0.52-1 Severity: important While trying to upgrade an older libapache2-mod-php4, apache2-mpm-worker should be removed. But the removal failed, because /etc/init.d/apache2 stop returned an error code (because apache2 was already stopped before). The

Bug#279865: acknowledged by developer (Re: Bug#279865: apache-common: CAN-2004-0940 Vulnerable?)

2004-11-05 Thread Helge Kreutzmann
Hello, On Fri, Nov 05, 2004 at 06:18:12AM -0800, Debian Bug Tracking System wrote: Thanks for reporting this twice already. Please before filing bugs you are welcome to check both debian-apache mailing lists and bugs.debian.org/src:apache. I *did* check the bts (though admitingly without

Bug#279865: acknowledged by developer (Re: Bug#279865: apache-common: CAN-2004-0940 Vulnerable?)

2004-11-05 Thread Fabio Massimo Di Nitto
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Helge Kreutzmann wrote: | Hello, | On Fri, Nov 05, 2004 at 06:18:12AM -0800, Debian Bug Tracking System wrote: | |Thanks for reporting this twice already. Please before filing bugs you are welcome to check both |debian-apache mailing lists and

Processed: RE: Bug#279875: removing apache2-mpm-worker fails

2004-11-05 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: reassign 279875 apache-common Bug#279875: removing apache2-mpm-worker fails Bug reassigned from package `apache2-mpm-worker' to `apache-common'. severity 279875 normal Bug#279875: removing apache2-mpm-worker fails Severity set to `normal'. reassign

Bug#237377: unsure if I am suffering the same tihng

2004-11-05 Thread Adam Conrad
Dave Ewart wrote: FWIW, for me, a manual '/etc/init.d/apache reload' *does* cause the problem too. My difficulty therefore reduces completely to be /etc/init.d/apache reload makes Apache die. Apache is version 1.3.26-0woody5 and included PHP support (version 4.1.2-7.0.1) - on a Woody