Bug#566325: bozohttpd: crashes on invalid input

2010-01-29 Thread Andrew Varner
Cool, thank you. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#566325: bozohttpd: crashes on invalid input

2010-01-26 Thread matthew green
hi. i'm the author of bozohttpd. this isn't a DoS or security problem. i only noticed this after there was a secunia notice about one. i've mailed them about this as well to inform them that their notice is wrong. in inetd or daemon mode, the double free() occurs in the child process, not the

Bug#566325: bozohttpd: crashes on invalid input

2010-01-22 Thread Andrew Varner
Subject: bozohttpd: crashes on invalid input Package: bozohttpd Version: 20090522-1 Severity: grave Justification: user security hole Tags: security *** Please type your report below this line *** bozohttpd crashes with the input 'GET HTTP/1.0\n\n'. (The correct input would have a '/' after 'GET')