Bug 132741
Summary: | CAN-2004-0747, 0748, 0751, 0809 | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Gilbert Sebenste <sebenste> |
Component: | httpd | Assignee: | Joe Orton <jorton> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 1 | CC: | bressers, djuran, rh |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.httpd.org | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2004-12-08 20:57:56 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Gilbert Sebenste
2004-09-16 16:11:04 UTC
apr-util updates to fix CAN-2004-0786 were issued yesterday. httpd updates are being prepared. Thank you! Will look forward to seeing them. Thanks much, and keep up the great work! Update are now available for FC1 from the testing repos: http://www.redhat.com/archives/fedora-test-list/2004-September/msg00609.html please post any feedback from testing these to this bug report. So far, so good! Just slapped them on 4 machines...no errors. Thank you! Thanks. Please leave this open until the updates are shipped to final. A few hours after update, http authentiaction in .htaccess did not work and search engine crawler bots were able to get to admin parts of our web and delete some items from database... But I don't know how to reproduce. What is the configuration in said .htaccess file? We need to determine whether that was a real bug and whether it was related to the 2.0.51 update. It was: AuthName "[somewhat]" AuthUserFile /var/www/[somewhat]/html/admin/.htpasswd AuthType Basic Require valid-user I noticed, that it does it exactly after one hour of running. And you checked, no username was logged in access_log for the accesses by the crawler? I tested if I can reproduce it, so I did a "while :; do wget -O /dev/null http://[somewhat]/admin/; sleep 1; done" and it stopped returning 401 after exactly one hour and no username was logged. "one hour" sounds like a possible caching issue. Do you have mod_mem_cache or any other caching configured for this site? I did not touch any configuration relating mod_*cache, so if it's not enabled by default, I don't have it enabled. Are you using the prefork MPM, not worker? I can't reproduce any problems from a similar setup running for several hours. Can you: 1) attach your complete httpd.conf and any other changed conf.d/*.conf files. 2) downgrade again to the 2.0.50 packages and check that the problem is not reproducible there. Tomas' bug was confirmed as a Satisfy handling regression in 2.0.51. But now this update will have to be issued via Fedora Legacy, so I'll try and co-ordinate with them. Thx, is it also ok in Fedora Core 2? (I'm now upgrading mashines) Updates which include all the above fixes will be issued for FC2 soon. The FC2 2.0.51 updates have not been pushed to live, so the FC2 httpd is vulnerable to all the CAN numbers in the Summary, but not the Satisfy regression. I'm afraid, but it's vulnerable to the satisfy regression (or something with same effects) too :( The fix for FC2 was FEDORA-2004-313: http://www.redhat.com/archives/fedora-announce-list/2004-September/msg00029.html fixes for FC1 must now be handled by the Fedora Legacy team. |