[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-09 Thread Launchpad Bug Tracker
This bug was fixed in the package libfcgi - 2.4.0-8.1ubuntu0.1 --- libfcgi (2.4.0-8.1ubuntu0.1) precise-security; urgency=low * Applying patch to swap select with poll to handle more than 1024 connections and avoid data corruption or a segfault. (LP: #1418778). -- Joe Damato

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-06 Thread Kees Cook
Today I learned that Apache raises its rlimit for open files to 8192 by default. This is controlled by APACHE_ULIMIT_MAX_FILES. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libfcgi in Ubuntu. https://bugs.launchpad.net/bugs/1418778

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-06 Thread Marc Deslauriers
Actually, it will be published on monday as we don't typically publish updates on friday. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libfcgi in Ubuntu. https://bugs.launchpad.net/bugs/1418778 Title: Stack smashing while using a

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-06 Thread Marc Deslauriers
ACK on the debdiff. Looks good. Uploaded for building with a slight version change, and will be released today. Thanks! ** Changed in: libfcgi (Ubuntu Precise) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Server Team, which i

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-06 Thread Marc Deslauriers
** Also affects: libfcgi (Ubuntu Precise) Importance: Undecided Status: New ** Changed in: libfcgi (Ubuntu Precise) Status: New => Confirmed ** Changed in: libfcgi (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubun

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-05 Thread Thomas Ward
(NOTE: Importance change is done to match the previous bug, #933417. It can be changed at the Security Team's discretion.) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libfcgi in Ubuntu. https://bugs.launchpad.net/bugs/1418778 Titl

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-05 Thread Thomas Ward
Please make a note: I have nominated this bug for the Precise series. When the Precise series is approved on this bug, the status for the development-release (i.e. the 'no series' bug which is implied for the in-development release) should be set to "Fix Released" as this issue has been fixed with

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-05 Thread Thomas Ward
Note on the debdiff: The wrong bug number is present in the debdiff (the old one). Since that bug is now "fixed" we would be using the new bug number here. I've attached the same debdiff with a one line revision to correct the bug number. Still has the original debdiff author's fingerprints all

[Bug 1418778] Re: Stack smashing while using a lot of connections

2015-02-05 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libfcgi in Ubuntu. https://bugs.launchpad.net/bugs/1418778 Title: Stack smashing while using a lot of connections T