Christoph Schnauß: Apache 1.3.24 released

Beitrag lesen

hallo Wolfgang ;-)

Leider sind die beschriebenen Bugfixes und Upgrades nicht
so wild....Ein Update kann für mich also noch ne Weile warten.

das sehe ich "eigentlich" auch so.

(Natürlich würde ich anders sprechen, würde ich meinen Apache auf
einem Ex-Floppysystem betreiben :) )

ähm ... was ist daran so natürlich und darf ich ('tschuldigung) unter einem Ex-Floppy-System etwas vermuten, was ursprünglich mal _ausschließlich_ von einer Diskette aus gestartet werden sollen sollte ( "werden sollen sollte" ist korrekt)

Ich habe natürlich gelesen:
If you will install Apache on Windows XP, be warned. There is a known bug our users have identified; you may or may not encounter it yourself. It is mitigated but possibly not eliminated with the Apache 1.3.24 release. The effects of this bug within Apache 2.0 Beta are not yet observed.

It appears the combination of duplicating file handles between and parent and child process, in conjunction with blocking sends to the http client, may result in corrupted output. You may not see this in MSIE, which tends to throw any error in the 'Cannot find server or DNS Error' category, rather than display the corruption. You will only see this corruption over slower links, testing the local loopback generally reveals no corruption. This is a potential security risk, since the random, corrupt data served may come from anywhere, such as the cache of buffered file pages, and these may include sensitive contents.

If you receive such errors on Windows XP using SSI scripting or PHP scripts, but not static pages, you are probably a victim of this bug. It has been reported to Microsoft, we understand they are preparing a hotfix for afd.sys that addresses this bug. MSKB article Q317949 has been reserved for this issue, you should be able to obtain this hotfix citing this [yet unpublished] Knowledge Base article.

aha, man muß also dem Inhalt eines "yet unpublished" Artikels vertrauen

Grüße aus Berlin

Christoph S.