You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@httpd.apache.org by Chuck Murcko <ch...@n2k.com> on 1997/01/13 17:10:20 UTC

Re: Security release: Apache 1.1.2 (fwd)

Not acked.

Jens Schleusener liltingly intones:
> From Jens.Schleusener@dlr.de@telebase.com  Mon Jan 13 09:56:17 1997
> Date: Mon, 13 Jan 1997 15:51:01 +0100 (NFT)
> From: Jens Schleusener <Je...@dlr.de>
> To: apache@apache.org
> Subject: Re: Security release: Apache 1.1.2
> In-Reply-To: <5b...@re.hotwired.com>
> Message-ID: <Pi...@dv.go.dlr.de>
> MIME-Version: 1.0
> Content-Type: TEXT/PLAIN; charset=US-ASCII
> 
> Hallo,
> 
> just for information a short observation regarding the use of the program
> "uncgi":
> 
> After applying your recommendend patch to Apache 1.1.1 the following
> problem occurs under AIX 4.1.4 using the program "uncgi" (extract from
> the error_log): 
> 
>  [Mon Jan 13 13:59:31 1997] access to /usr/local/www/cgi-bin/uncgi/ffmail
>  failed for client; unable to determine if index file exists (stat()
>  returned unexpected error)
> 
> This error text is - as you know - part of the patch. "ffmail" is a
> self-written CGI-script using "uncgi", "a frontend for processing queries
> and forms from the Web on UNIX systems". 
> 
> Using Apache 1.2b4 that problem doesn't occur !
> 
> Jens Schleusener
> 
> --
> Dr. Jens Schleusener (WT-DV)    DLR (German Aerospace Research Establishment) 
> phone: +49 (551) 709-2493       Bunsenstr.10
> fax:   +49 (551) 709-2169       D-37073 Goettingen
> email: Jens.Schleusener@dlr.de  Germany
> 
> 

chuck
Chuck Murcko	N2K Inc.	Wayne PA	chuck@telebase.com
And now, on a lighter note:
A baby is an alimentary canal with a loud voice at one end and no
responsibility at the other.

Re: Security release: Apache 1.1.2 (fwd)

Posted by Marc Slemko <ma...@znep.com>.
See my other message for the problem.

Sigh.  The more cases we have to check, the less portable it gets.  Seeing
as we managed to screw up both patches in 1.1.2... sigh.

On Mon, 13 Jan 1997, Chuck Murcko wrote:

> Not acked.
> 
> Jens Schleusener liltingly intones:
> > From Jens.Schleusener@dlr.de@telebase.com  Mon Jan 13 09:56:17 1997
> > Date: Mon, 13 Jan 1997 15:51:01 +0100 (NFT)
> > From: Jens Schleusener <Je...@dlr.de>
> > To: apache@apache.org
> > Subject: Re: Security release: Apache 1.1.2
> > In-Reply-To: <5b...@re.hotwired.com>
> > Message-ID: <Pi...@dv.go.dlr.de>
> > MIME-Version: 1.0
> > Content-Type: TEXT/PLAIN; charset=US-ASCII
> > 
> > Hallo,
> > 
> > just for information a short observation regarding the use of the program
> > "uncgi":
> > 
> > After applying your recommendend patch to Apache 1.1.1 the following
> > problem occurs under AIX 4.1.4 using the program "uncgi" (extract from
> > the error_log): 
> > 
> >  [Mon Jan 13 13:59:31 1997] access to /usr/local/www/cgi-bin/uncgi/ffmail
> >  failed for client; unable to determine if index file exists (stat()
> >  returned unexpected error)
> > 
> > This error text is - as you know - part of the patch. "ffmail" is a
> > self-written CGI-script using "uncgi", "a frontend for processing queries
> > and forms from the Web on UNIX systems". 
> > 
> > Using Apache 1.2b4 that problem doesn't occur !
> > 
> > Jens Schleusener
> > 
> > --
> > Dr. Jens Schleusener (WT-DV)    DLR (German Aerospace Research Establishment) 
> > phone: +49 (551) 709-2493       Bunsenstr.10
> > fax:   +49 (551) 709-2169       D-37073 Goettingen
> > email: Jens.Schleusener@dlr.de  Germany
> > 
> > 
> 
> chuck
> Chuck Murcko	N2K Inc.	Wayne PA	chuck@telebase.com
> And now, on a lighter note:
> A baby is an alimentary canal with a loud voice at one end and no
> responsibility at the other.
>