Re: Apache 2.x leaked descriptors

From: Christian Kratzer (ck@cksoft.de)
Date: 02/24/03

  • Next message: Michael Wojcik: "RE: Apache 2.x leaked descriptors"
    Date: Mon, 24 Feb 2003 22:58:50 +0100 (CET)
    From: Christian Kratzer <ck@cksoft.de>
    To: "David M. Wilson" <dw-securityfocus.com@botanicus.net>
    
    

    Hi,

    On Mon, 24 Feb 2003, David M. Wilson wrote:

    > On Sat, Feb 22, 2003 at 02:46:59PM -0800, jon schatz wrote:
    [snipp]
    > Ideal permissions on CGI directories do not differ to the permissions on
    > other content directories. I think you may be confused as to what
    > execute permission actually means:

    the point about leaked file descriptors is not about execute permissions.

    Apache 2.0 currently execs cgi scripts / server side includes etc... with
    file descriptors open to all access and error logs on the server and also
    to a couple of internal pipes.

    This means any cgi script can muck around with all access and error logs,
    read them, truncate them, overwrite them or append funny stuff.

    There is a bug in apache 2.0 that prevents closing of these internal resources
    before running the cgi's.

    Thats all. And thats enough ...

    Greetings
    Christian

    -- 
    CK Software GmbH
    Christian Kratzer,           Schwarzwaldstr. 31, 71131 Jettingen
    Email:	ck@cksoft.de
    Phone: 	+49 7452 889-135     Open Software Solutions, Network Security
    Fax: 	+49 7452 889-136     FreeBSD spoken here!
    


    Relevant Pages

    • Re: [SLE] About permissions on C
      ... > Thats happens after i installed windows whit service pack 2. ... the permissions are set ... You need to change the fstab mounting options either by ... One more thing - if you use YaST, it will remount the partition after the ...
      (SuSE)
    • Re: [SLE] Problem with K3b and 9.1 [SOLVED - MAYBE]
      ... >You may want to add the permissions of cdrdao and cdrecord ... Thats the setting I have. ...
      (SuSE)
    • Re: unable to use "ipcs" as a non-root
      ... Thats the exact solution.....Somehow, it didnot occur to ... me to check the permissions of /usr/bin/ipcs. ...
      (comp.unix.aix)
    • Re: Activex Scripting : Function Not found Error
      ... Thats right. ... It does not work in DTS. ... I scheduled as a Job also thinking its related to permissions of the ... server. ...
      (microsoft.public.sqlserver.dts)
    • Re: default permissions when scping files
      ... In comp.unix.shell RobR: ... >> would save you much trouble. ... > i made it clear thats not what im looking for. ... source permissions and would like to keep the permissions remote, ...
      (comp.unix.shell)