<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Apache | Dev</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/apache/dev/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>16 May  2008 14:55:15 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Apache | Dev</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/apache/dev/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Debian gaffe (DSA-1571-1, CVE-2008-016)</title>
<description>The debian gaffe also affects any &amp;#039;req&amp;#039;s or self-signed certs created  on the affected platform. Unfortunately the blacklists generated by folks are</description>
<pubDate>16 May  2008 13:11:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351684</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by interproceduralcode analysis for version 2.2.8 of Apache</title>
<description>On May 15, 2008, at 3:00 PM, Ruediger Pluem wrote: &amp;gt; &amp;gt; &amp;gt; On 05/15/2008 05:29 AM, BOYA SUN wrote: &amp;gt;&amp;gt; Here is another potential bug we&amp;#039;ve just discover</description>
<pubDate>16 May  2008 05:06:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351665</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by interproceduralcode analysis for version 2.2.8 of Apache</title>
<description>On tor, 2008-05-15 at 21:07 +0100, John ORourke wrote: &amp;gt; This error would typically happen on a busy site with a full log &amp;gt; partition. Writing to sy</description>
<pubDate>16 May  2008 02:34:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351663</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by	interproceduralcode analysis for version 2.2.8 of Apache</title>
<description>Henrik Nordstrom wrote: &amp;gt; On tor, 2008-05-15 at 21:00 +0200, Ruediger Pluem wrote: &amp;gt;  &amp;gt;&amp;gt;&amp;gt; \apache\src\log.c(682):    apr_file_puts(errstr, logf</description>
<pubDate>15 May  2008 13:07:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351658</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by	interproceduralcode analysis for version 2.2.8 of Apache</title>
<description>On 05/15/2008 09:44 PM, Henrik Nordstrom wrote: &amp;gt; On tor, 2008-05-15 at 21:00 +0200, Ruediger Pluem wrote: &amp;gt;&amp;gt;&amp;gt; \apache\src\log.c(682):    apr_fil</description>
<pubDate>15 May  2008 13:04:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351657</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by interproceduralcode analysis for version 2.2.8 of Apache</title>
<description>On tor, 2008-05-15 at 21:00 +0200, Ruediger Pluem wrote: &amp;gt; &amp;gt; \apache\src\log.c(682):    apr_file_puts(errstr, logf); &amp;gt; &amp;gt; I see nothing reasonabl</description>
<pubDate>15 May  2008 12:44:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351656</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by interproceduralcode analysis for version 2.2.8 of Apache</title>
<description>On 05/15/2008 05:29 AM, BOYA SUN wrote: &amp;gt; Here is another potential bug we&amp;#039;ve just discovered, and it seems to be occured in several places. Please al</description>
<pubDate>15 May  2008 12:00:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351654</link>
</item><item>
<title>[PATCH] Response to TRACE garbled from EBCDIC platform</title>
<description>The response to TRACE when &amp;quot;TraceEnable Off&amp;quot; is not used on an EBCDIC platform is partially in ASCII and partially in EBCDIC (part readable, part garb</description>
<pubDate>15 May  2008 10:54:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351653</link>
</item><item>
<title>Re: Re: bugs/inappropriate coding practice discovered by interproceduralcode analysis for version 2.2.8 of Apache</title>
<description>Here is another potential bug we&amp;#039;ve just discovered, and it seems to be occured in several places. Please also take a look at it if interested, thanks</description>
<pubDate>14 May  2008 20:20:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351629</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by interprocedural code analysis for version 2.2.8 of Apache</title>
<description>On 05/14/2008 10:19 PM, Paul Querna wrote: &amp;gt; BOYA SUN wrote: &amp;gt; &amp;gt;&amp;gt; *BUG#1* &amp;gt;&amp;gt; *Category: 1* &amp;gt;&amp;gt; *File Name:* /httpd-2.2.8/support/ab.c *Function Name</description>
<pubDate>14 May  2008 13:43:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351618</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by interprocedural code analysis for version 2.2.8 of Apache</title>
<description>Dear Paul, Thank you so much for replying to the email. It seems that our approach is accurate in finding bugs of Category 1, but not so accurate for</description>
<pubDate>14 May  2008 13:40:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351617</link>
</item><item>
<title>Re: User/group security without CGI (SuEXEC)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yes, but as stated in my email, suphp uses cgi, which I don&amp;#039;t like (unnecessary exec()&amp;#039;s), and is the e</description>
<pubDate>14 May  2008 13:22:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351616</link>
</item><item>
<title>Re: bugs/inappropriate coding practice discovered by interprocedural code analysis for version 2.2.8 of Apache</title>
<description>BOYA SUN wrote: &amp;gt; Dear Apache-HTTPD developers, &amp;gt;  &amp;gt; I am a Ph.D student in the Software Engineering Research Group of EECS &amp;gt; department in Case Wes</description>
<pubDate>14 May  2008 13:19:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351615</link>
</item><item>
<title>bugs/inappropriate coding practice discovered by interprocedural code analysis for version 2.2.8 of Apache</title>
<description>Dear Apache-HTTPD developers,  I am a Ph.D student in the Software Engineering Research Group of EECS department in Case Western Reserve University,</description>
<pubDate>14 May  2008 11:44:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351609</link>
</item><item>
<title>Re: User/group security without CGI (SuEXEC)</title>
<description>Hi, &amp;gt;&amp;gt;&amp;gt; How do you think about this idea ? do you already know this: http://www.suphp.org/ Guenter.</description>
<pubDate>14 May  2008 10:51:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351608</link>
</item><item>
<title>Correction to BID 29112 &amp;quot;Apache Server HTML Injection and UTF-7 XSS Vulnerability&amp;quot;</title>
<description>HTTP User and Desktop Security Communities; With respect to http://www.securityfocus.com/bid/29112 Per http://www.ietf.org/rfc/rfc2616.txt 3.7.1 Ca</description>
<pubDate>14 May  2008 10:27:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351607</link>
</item><item>
<title>Re: CVE-2008-2168</title>
<description>Nick Gearls wrote: &amp;gt; &amp;gt; Cross-site scripting (XSS) vulnerability when displaying the 403 &amp;gt; Forbidden error page &amp;gt; I can&amp;#039;t find any info about this is</description>
<pubDate>14 May  2008 10:14:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351605</link>
</item><item>
<title>CVE-2008-2168</title>
<description>&amp;gt; Cross-site scripting (XSS) vulnerability when displaying the 403 Forbidden error page I can&amp;#039;t find any info about this issue on the site. I guess</description>
<pubDate>14 May  2008 04:35:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351590</link>
</item><item>
<title>Re: [PATCH] DTrace probes patch.</title>
<description>&amp;gt; I see no issues with making this the default and having a --disable-dtrace. &amp;gt; I can see a reason that someone might wish to turn them off -- thoug</description>
<pubDate>13 May  2008 17:49:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351565</link>
</item><item>
<title>Impact of OpenSSL Randomness issues on Debian</title>
<description>If you are just catching up: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0166 http://it.slashdot.org/article.pl?sid=08/05/13/1533212 Most of the tal</description>
<pubDate>13 May  2008 14:18:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351562</link>
</item><item>
<title>Missing vote for persistent SSL backend proxy connections</title>
<description>I know that the following patch really requires some work to review, but it is missing only one vote and it would be really worth to be included in 2.</description>
<pubDate>13 May  2008 14:02:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351561</link>
</item><item>
<title>Re: svn commit: r655711 - in /httpd/httpd/trunk: CHANGES support/suexec.c</title>
<description>On 05/13/2008 04:21 AM, fielding@apache.org wrote: &amp;gt; Author: fielding &amp;gt; Date: Mon May 12 19:21:33 2008 &amp;gt; New Revision: 655711 &amp;gt; &amp;gt; URL: http://svn.apa</description>
<pubDate>13 May  2008 12:30:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351560</link>
</item><item>
<title>Re: svn commit: r655594 - /httpd/httpd/branches/2.2.x/STATUS</title>
<description>On 05/12/2008 08:39 PM, jim@apache.org wrote: &amp;gt; Author: jim &amp;gt; Date: Mon May 12 11:39:34 2008 &amp;gt; New Revision: 655594 &amp;gt; &amp;gt; URL: http://svn.apache.org/vi</description>
<pubDate>12 May  2008 13:33:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351478</link>
</item><item>
<title>Re: mod_proxy race condition bug #37770</title>
<description>I haven&amp;#039;t looked at the code in mod_proxy to see how it handles the Keep-Alive header returned by the backend server, but what I&amp;#039;m seeing in this tcpd</description>
<pubDate>12 May  2008 13:15:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351477</link>
</item><item>
<title>Re: mod_proxy race condition bug #37770</title>
<description>On Mon, 12 May 2008 13:52:18 -0400 &amp;quot;Adam Woodworth&amp;quot; &amp;lt;mirkperl@gmail.com&amp;gt; wrote: &amp;gt; Hi, &amp;gt; &amp;gt; I was wondering if anyone might have some more information</description>
<pubDate>12 May  2008 12:31:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/351476</link>
</item>
</channel>
</rss>
