[users@httpd] Question about 2.4.56 "client resets of HTTP/2 streams led to unwanted 500 errors" fix

2023-03-13 Thread Robert L Mathews
After upgrading from httpd 2.4.54 to 2.4.55, I noticed that mod_fcgid scripts would sometimes get "stuck" in the "working" state, rather than the "ready" state, even though the script associated with the mod_fcgid slot was idle and waiting for a new request. While investigating, I noticed this

Re: [users@httpd] CVE-2023-25690: Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy

2023-03-13 Thread Eric Covener
On Mon, Mar 13, 2023 at 7:38 AM Thomas Åkesson wrote: > > > Try e.g. [R,B= ?,...] > > The question mark is to avoid the issue of not being able to have " " > as the final character in this syntax. > >>> > >> > >> Sorry, the above doesn't work. Someone reported in another thread

Re: [users@httpd] CVE-2023-25690: Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy

2023-03-13 Thread Thomas Åkesson
>>> Thanks for the suggestion. I am unable to make 2.4.52 (Ubuntu) accept space >>> for the B-flag. I have tried first, middle, last, only flag but always >>> getting "RewriteRule: bad flag delimiters". >>> >>> I am also having concerns whether this would work (unable to test at this >>> time

Re: [users@httpd] CVE-2023-25690: Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy

2023-03-13 Thread Thomas Åkesson
Try e.g. [R,B= ?,...] The question mark is to avoid the issue of not being able to have " " as the final character in this syntax. >>> >> >> Sorry, the above doesn't work. Someone reported in another thread: [R,B=\ ] > > The real trick seems to be quoting the entirety of t

Re: [users@httpd] apache questions

2023-03-13 Thread Deepak Goel
The jvm once grown to its full size (RAM) will keep the RAM. But the JVM will release all old objects so your new users can access your website. Why would you want to release the RAM? Deepak "The greatness of a nation can be judged by the way its animals are treated - Mahatma Gandhi" +91 73500 1