Vulnerability Development mailing list archives

Re: Another flaw in Apache?


From: Jedi/Sector One <j () pureftpd org>
Date: Sun, 23 Jun 2002 09:15:00 +0200

  Further investigation show that the flaw is not in Apache itself, but in
mod_ssl, so it's probably not an OpenBSD-specific bug. It's just not
triggered on systems where mod_ssl isn't compiled in.

  The overflow is the ssl_compat_directive() function in
src/modules/ssl/ssl_engine_compat.c .

-- 
 __  /*-      Frank DENIS (Jedi/Sector One) <j () 42-Networks Com>     -*\  __
 \ '/    <a href="http://www.PureFTPd.Org/";> Secure FTP Server </a>    \' /
  \/  <a href="http://www.Jedi.Claranet.Fr/";> Misc. free software </a>  \/


Current thread: