Date: Mon, 21 Mar 2011 22:49:27 +0100 From: "Steinar H. Gunderson" <sgunderson@...foot.com> To: Josh Bressers <bressers@...hat.com> Cc: oss-security@...ts.openwall.com, team@...urity.debian.org Subject: Re: CVE request: MPM-ITK module for Apache HTTPD On Mon, Mar 21, 2011 at 04:24:38PM -0400, Josh Bressers wrote: >> In certain configurations, the MPM-ITK module for Apache HTTPD serves >> a >> request as root user instead of the run user configured in the HTTPD >> configuration: >> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857 > Please use CVE-2011-1176 Thanks. Here are the relevant announcements (with patches): http://lists.err.no/pipermail/mpm-itk/2011-March/000393.html http://lists.err.no/pipermail/mpm-itk/2011-March/000394.html /* Steinar */ -- Homepage: http://www.sesse.net/
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.