|
|||||||||||
|
Re: Apache 2.x leaked descriptors
From: Christian Kratzer <ck(at)cksoft.de>
Date: Mon Feb 24 2003 - 16:58:50 EST Hi, On Mon, 24 Feb 2003, David M. Wilson wrote: > On Sat, Feb 22, 2003 at 02:46:59PM -0800, jon schatz wrote:
the point about leaked file descriptors is not about execute permissions. This means any cgi script can muck around with all access and error logs, read them, truncate them, overwrite them or append funny stuff. There is a bug in apache 2.0 that prevents closing of these internal resources before running the cgi's. Thats all. And thats enough ...
Greetings
-- CK Software GmbH Christian Kratzer, Schwarzwaldstr. 31, 71131 Jettingen Email: ck@cksoft.de Phone: +49 7452 889-135 Open Software Solutions, Network Security Fax: +49 7452 889-136 FreeBSD spoken here!Received on Tue Feb 25 12:19:43 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:38 EDT |
||||||||||
|
|||||||||||