[H-GEN] apache updates (mime exploit)

Bruce Campbell bc at humbug.org.au
Thu Jun 20 03:55:46 EDT 2002


[ Humbug *General* list - semi-serious discussions about Humbug and     ]
[ Unix-related topics. Posts from non-subscribed addresses will vanish. ]

On Thu, 20 Jun 2002, Tony Nugent wrote:

> What suprises me (well, perhaps it shouldn't:) is that at exactly
> the same time that this is happening, micro$oft are also issuing
> updates for many of its products (iis, m$IE, outrage, m$office, etc)
> to fix problems that appear to relate to exactly the same issue
> (involving "chunked" encoding).

Its a similar problem to the SNMP exploits earlier this year in a number
of divergent (but with a common ancestor) code-bases.  A problem with one
code-base has been discovered, and other code-bases are thus being
explored for the same problem, in case the same misinterpretation or code
is present.

> The conclusion that I'm inclined to make (from my viewpoint anyway)
> is that (closed-source) m$II$ and (open-source) apache share a
> common code base.  Which should not be the case, and if it is then
> m$ may have some questions to answer.

Why should this (MS copying and using open-source code) not be the case?

If you argue it another way, you could claim that those portions of MS
products are known to be 'Good' ;)

--==--
Bruce.


--
* This is list (humbug) general handled by majordomo at lists.humbug.org.au .
* Postings to this list are only accepted from subscribed addresses of
* lists 'general' or 'general-post'.  See http://www.humbug.org.au/



More information about the General mailing list