Re: [users@httpd] AH00051: child pid 3886730 exit signal Segmentation fault (11), possible coredump in /etc/httpd

2024-09-27 Thread Eric Covener
Send the backtrace of all threads as an attachment or open a bug report and attach it there. https://bz.apache.org/bugzilla/enter_bug.cgi?product=Apache%20httpd-2&Bugzilla_remember=on&Bugzilla_restrictlogin=on&GoAheadAndLogIn=Log%20in On Fri, Sep 27, 2024 at 8:31 PM Dave Wreski wrote: > > I'm usi

Re: [users@httpd] AH00051: child pid 3886730 exit signal Segmentation fault (11), possible coredump in /etc/httpd

2024-09-27 Thread Dave Wreski
I'm using httpd-2.4.62 on fedora40 and noticed periodic errors related to core dumps. Is this a potential bug? I see there are several similar bug reports with previous versions but never a resolution. The crash symptom by iteslf doesn't mean very much without specific backtraceshttps://httpd.a

[users@httpd] How to fix Apache HTTPD Unauthenticated/Open Web Proxy Vulnerability?

2024-09-27 Thread Shinde, Pramod K
Hello, We are using Apache HTTPD 2.4.53 for an internal content management system. It is not customer-facing. The security solution considers the proxy vulnerable to an "Unauthenticated/Open Web Proxy Detected" vulnerability. After many back and forths with them to check if it's a false positiv

Re: [users@httpd] AH00051: child pid 3886730 exit signal Segmentation fault (11), possible coredump in /etc/httpd

2024-09-27 Thread Dave Wreski
Hi, I'm using httpd-2.4.62 on fedora40 and noticed periodic errors related to core dumps. Is this a potential bug? I see there are several similar bug reports with previous versions but never a resolution. [Wed Sep 25 11:07:16.786647 2024] [core:notice] [pid 1616:tid 161

Re: [users@httpd] How to fix Apache HTTPD Unauthenticated/Open Web Proxy Vulnerability?

2024-09-27 Thread Eric Covener
I suspect you are not running a forward proxy on purpose, so you should not have "ProxyRequests ON" in your configuration. You should just test without this, remove the other additions, and move on. If you're running a forward proxy on purpose, you have to restrict who can access it (and what hos

Re: [users@httpd] AH00051: child pid 3886730 exit signal Segmentation fault (11), possible coredump in /etc/httpd

2024-09-27 Thread Eric Covener
On Thu, Sep 26, 2024 at 10:26 PM Dave Wreski wrote: > > Hi, > > I'm using httpd-2.4.62 on fedora40 and noticed periodic errors related to > core dumps. Is this a potential bug? I see there are several similar bug > reports with previous versions but never a resolution. The crash symptom by ites