Re: apache and CAN-2003-0020

2005-03-24 Thread Joey Hess
Geoff Crompton wrote: > CAN-2003-0020 is a vulnerability in apache that mentions how apache > allows escape sequences into the error logs, which might exploit a > terminal program viewing them. > More detail is at http://www.securityfocus.com/bid/9930. The > securityfocus page lists Debian as be

Re: apache and CAN-2003-0020

2005-03-22 Thread Christophe Chisogne
Geoff Crompton a écrit : I can't find a DSA that corresponds to CAN-2003-0020. Woody isnt affected[1] : CAN-2003-0020: Apache: Missing filter for terminal escape sequences from error logs Ch. [1] Non-Vulnerability Security Information for woody http://www.nl.debian.org/security/nonvulns-woody

apache and CAN-2003-0020

2005-03-22 Thread Geoff Crompton
CAN-2003-0020 is a vulnerability in apache that mentions how apache allows escape sequences into the error logs, which might exploit a terminal program viewing them. More detail is at http://www.securityfocus.com/bid/9930. The securityfocus page lists Debian as being vulnerable, and I can't find