Re: hanging apache processes (1.3.29 + mod_ssl 2.8.9)

2002-06-23 Thread Cliff Woolley
On Sun, 23 Jun 2002, Alex Kotov wrote: > After a while the server processes become stuck while waiting for > the data from a socket. > Running strace on a hung process produces > read(5, > for a long time, eventually followed by > read(5, 0x959d2d8, 11) = -1 ETIMEDOUT (Connection timed out) Are

hanging apache processes (1.3.29 + mod_ssl 2.8.9)

2002-06-23 Thread Alex Kotov
We have a strange problem with our Apache+mod_ssl server (Apache/1.3.26 (Unix) mod_perl/1.22 mod_ssl/2.8.9 OpenSSL/0.9.6, on Linux 2.2.19). After a while the server processes become stuck while waiting for the data from a socket. The timeout is set to 300 in httpd.conf, but the processes happily

[BugDB] Buffer overflow in mod_ssl (patch enclosed) (PR#724)

2002-06-23 Thread modssl-bugdb
Full_Name: Frank Denis - Jedi/Sector One Version: 2.8.8 (OpenBSD-current) OS: OpenBSD Submission from: (NULL) (212.198.0.93) There's an easy to exploit (through .htaccess files) buffer overflow in mod_ssl. The EAPI's rewrite parser hook skips spaces without checking whether the pointer went past