[Bug 1836329] Re: Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS

2019-07-15 Thread Andreas Hasenack
** Changed in: apache2 (Ubuntu) Status: Incomplete => In Progress -- You received this bug notification because you are a member of Ubuntu Server, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/1836329 Title: Regression running ssllabs.com/ssltest causes 2

[Bug 1836329] Re: Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS

2019-07-15 Thread Andreas Hasenack
** CVE removed: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3555 ** CVE removed: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-3389 ** CVE removed: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2012-4929 ** CVE removed: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2013-0169 **

[Bug 1836329] Re: Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS

2019-07-15 Thread Andreas Hasenack
Disco is also clean, as expected. ** Also affects: apache2 (Ubuntu Disco) Importance: Undecided Status: New ** Changed in: apache2 (Ubuntu Disco) Status: New => Fix Released ** Changed in: apache2 (Ubuntu Eoan) Importance: Critical => Undecided ** Changed in: apache2

[Bug 1836329] Re: Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS

2019-07-15 Thread Andreas Hasenack
Actually, disco and eoan never had this bug, so the correct status for those tasks is "invalid". ** Changed in: apache2 (Ubuntu Disco) Status: Fix Released => Invalid ** Changed in: apache2 (Ubuntu Eoan) Status: Fix Released => Invalid -- You received this bug notification

[Bug 1836329] Re: Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS

2019-07-15 Thread Andreas Hasenack
I applied https://github.com/apache/httpd/commit/524608b65ec410e797a7283e6e142f8e5a74be26 and https://github.com/apache/httpd/commit/7fa21ea6602b30cc43d4f485777545dd73bb25a6 and that seems to work. Will clean the packaging up with those patches, check if perhaps only one is needed. PPA with

[Bug 1836329] Re: Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS

2019-07-15 Thread Andreas Hasenack
eoan is fine ** Also affects: apache2 (Ubuntu Eoan) Importance: Critical Assignee: Andreas Hasenack (ahasenack) Status: In Progress ** Also affects: apache2 (Ubuntu Bionic) Importance: Undecided Status: New ** Changed in: apache2 (Ubuntu Bionic) Status: New => In

[Bug 1836329] Re: Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS

2019-07-15 Thread Andreas Hasenack
Cosmic affected (2.4.34-1ubuntu2.2) ** Also affects: apache2 (Ubuntu Cosmic) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/1836329 Title: