Re: Apache 0-day / apache-uaf / use after free bugs

2019-01-22 Thread Stefan Eissing
Thanks for the update, Stefan! > Am 22.01.2019 um 13:42 schrieb Stefan Sperling : > > On Tue, Jan 22, 2019 at 01:31:43PM +0100, Rainer Jung wrote: >> Here's the response we have compiled from Daniel, Stefan and others: >> >> https://bz.apache.org/bugzilla/show_bug.cgi?id=63098 > > FYI, I have

Re: Apache 0-day / apache-uaf / use after free bugs

2019-01-22 Thread Stefan Sperling
On Tue, Jan 22, 2019 at 01:31:43PM +0100, Rainer Jung wrote: > Here's the response we have compiled from Daniel, Stefan and others: > > https://bz.apache.org/bugzilla/show_bug.cgi?id=63098 FYI, I have disabled pool debugging in OpenBSD's port of APR. We are now using Yann's patch to force the

Re: Apache 0-day / apache-uaf / use after free bugs

2019-01-22 Thread Stefan Eissing
Thanks! I also wrote about the h2 related parts at https://icing.github.io/mod_h2/pool-debugging.html > Am 22.01.2019 um 13:31 schrieb Rainer Jung : > > Am 22.01.2019 um 10:33 schrieb Daniel Gruno: >> On 1/22/19 8:09 AM, Stefan Priebe - Profihost AG wrote: >>> Hi, >>> >>> in twitter and other

Re: Apache 0-day / apache-uaf / use after free bugs

2019-01-22 Thread Rainer Jung
Am 22.01.2019 um 10:33 schrieb Daniel Gruno: On 1/22/19 8:09 AM, Stefan Priebe - Profihost AG wrote: Hi, in twitter and other social media channels they're talking about a current apache 0 day: https://twitter.com/i/web/status/1087593706444730369 which wasn't handled / isn't currently fixed.

Re: Apache 0-day / apache-uaf / use after free bugs

2019-01-22 Thread Daniel Gruno
On 1/22/19 8:09 AM, Stefan Priebe - Profihost AG wrote: Hi, in twitter and other social media channels they're talking about a current apache 0 day: https://twitter.com/i/web/status/1087593706444730369 which wasn't handled / isn't currently fixed. Some details are here:

Apache 0-day / apache-uaf / use after free bugs

2019-01-21 Thread Stefan Priebe - Profihost AG
Hi, in twitter and other social media channels they're talking about a current apache 0 day: https://twitter.com/i/web/status/1087593706444730369 which wasn't handled / isn't currently fixed. Some details are here: https://github.com/hannob/apache-uaf If this is true there will be exploits