|
|||||||||||
|
Bug#453783: apache2: CVE-2007-4465
From: Stefan Fritsch <sf(at)sfritsch.de>
Date: Sat Dec 01 2007 - 06:47:24 EST
On Saturday 01 December 2007, you wrote:
If you can exploit that with Firefox, Firefox should be fixed. Can you give more details? I would be very interested. > Not really related to CVE-2006-5152. In fact that is a non-issue: Any broswer that interprets ascii as utf7 without being told to do so is severely buggy. And CVE-2006-5152 is about MSIE, not about Apache. Your retraction was about Apache. > > ... no plan to backport ... it is of low impact. If it affects only one buggy browser, it's low impact. And since the patch for the workaround is not that small (and is changing default behaviour and is adding a new config directive), I didn't want to backport it to stable. If it affects more browsers, I might reconsider. > > ... setting AddDefaultCharset also protects from the issue. AddDefaultCharset has some often unwanted side effects. It overrides the charset in meta http-equiv tags. See http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=397886 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=415775 It is not the default anymore in lenny and sid.
Cheers,
-- To UNSUBSCRIBE, email to debian-apache-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Sat Dec 1 06:54:57 2007 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 02:59:06 EDT |
||||||||||
|
|||||||||||