20 Jun
2002
20 Jun
'02
14:54
Yesterday's SuSE advisory (Apache chunk handling) indicates their belief that: On 32bit architectures, this overflow cannot be exploited to inject code into the httpd process and gain access to the machine, because the overflow will always result in a segmentation fault, and the process will terminate. However, the exploit posted this morning on vulnwatch indicates that such an exploit exists against Linux. This makes me wonder whether the SuSE patch is sufficient. (If they did not fully understand the threat, have they actually addressed it?) What is the official SuSE answer to this question? Thank you.