[php-maint] Bug#687307: Fwd: Updating php5 to 5.4.4-5 broke FastCGI setup on my machine
Christoph Anton Mitterer
calestyo at scientia.net
Thu Oct 11 01:18:22 UTC 2012
Oh and one more thing (even though this is PHP unrelated):
Maybe I misunderstand something but it seems both:
libapache2-mod-fcgid, which uses:
<IfModule mod_fcgid.c>
AddHandler fcgid-script .fcgi
FcgidConnectTimeout 20
</IfModule>
and
libapache2-mod-fastcgi, which uses:
<IfModule mod_fastcgi.c>
AddHandler fastcgi-script .fcgi
#FastCgiWrapper /usr/lib/apache2/suexec
FastCgiIpcDir /var/lib/apache2/fastcgi
</IfModule>
are highly vulnerable to the evil.fcgi.jpeg issue...
Can you confirm this? Cause then we need to open some critical bugs.
Cheers,
Chris.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5450 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-php-maint/attachments/20121011/47dab507/attachment-0001.bin>
More information about the pkg-php-maint
mailing list