Re: [OT] security!

2001-03-01 Thread Andrew Ho
Hello, GRBy looking the way modperl works today, it's clearly it were not GRdesgined to SECURELY support a multi-user environment. For instance: Any GRuser can write a script that will be able to read any file owned by the GRhttpd server, in a multi-user environment it should not be allowed.

[OT - Security] Linux vulnerability

2000-06-10 Thread Ged Haywood
Hi all, I thought this might be of interest to Apache users running Linux. A vulnerability in some versions of Linux has recently been identified. SYSTEMS AFFECTED Linux kernel versions 2.2.x before 2.2.16 (2.0.x are safe; 2.2.16 is safe) IMPACT Any local user can gain root

Re: [OT - Security] Linux vulnerability

2000-06-10 Thread Matt Sergeant
On Sat, 10 Jun 2000, Ged Haywood wrote: Hi all, I thought this might be of interest to Apache users running Linux. [snip] Note that this is not a vulnerability that Apache/Linux suffers from particularly, except in the case of a mod_perl or CGI exploit that allows the user to get a local