Bugtraq mailing list archives

Re: Vulnerability in NCSA HTTPD 1.3


From: rhaas () cygnus arc nasa gov (Robert M. Haas)
Date: Tue, 14 Feb 1995 20:59:05 -0800


CERN's httpd seems to be a bit smarter about this sort of thing, but it's
SO huge that even if they have only 10% as many bugs per K, they're worse
than NCSA.  (NCSA's src/* is 195K; CERN's WWW/Daemon/Implementation is
610K, plus WWW/Library/Implementation's 1406K(!).)

Are there known bugs in CERN's httpd? Is there a buglist? If so I would
appreciate a copy... 

I'm running CERN's httpd chroot'd, figuring that gives me a little room
for error. Am I kidding myself?

...Robert



Current thread: