RPC over HTTP

Bug #62820 reported by JB
6
Affects Status Importance Assigned to Milestone
apache2 (Ubuntu)
Invalid
Medium
Unassigned
Dapper
Invalid
Undecided
Unassigned

Bug Description

My Dapper webserver is configured as a reverse proxy which gets all the data from a Outlook Web Access Server.

I think it is the same bug report as here -> http://issues.apache.org/bugzilla/show_bug.cgi?id=37145
But the Bug isn´t fix.

Output error.log

[Thu Sep 28 18:35:14 2006] [error] (70007)The timeout specified has expired: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:36:39 2006] [error] (104)Connection reset by peer: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:38:19 2006] [error] (70007)The timeout specified has expired: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:39:45 2006] [error] (104)Connection reset by peer: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:51:48 2006] [error] (70007)The timeout specified has expired: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:53:13 2006] [error] (104)Connection reset by peer: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:54:53 2006] [error] (70007)The timeout specified has expired: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:56:19 2006] [error] (104)Connection reset by peer: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:57:59 2006] [error] (70007)The timeout specified has expired: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()
[Thu Sep 28 18:59:25 2006] [error] (104)Connection reset by peer: proxy: prefetch request body failed to 192.168.100.70 from 213.39.180.73 ()

Software info:

OS: Dapper Drake 6.06

apache2 - 2.0.55-4ubuntu2.1
apache2-common - 2.0.55-4ubuntu2.1
apache2-mpm-prefork - 2.0.55-4ubuntu2.1
apache2-utils - 2.0.55-4ubuntu2.1

Revision history for this message
JB (jb-ubuntu1804) wrote :

Hi,

here the patch!

Revision history for this message
Martin Pitt (pitti) wrote :
Changed in apache2:
status: Unconfirmed → Confirmed
Revision history for this message
Martin Pitt (pitti) wrote :

Will apply for edgy. Adam, if you feel a particular apache bug fixing seizure, feel free to grab this (or ask for UVF exception for 2.0.56 right away).

Changed in apache2:
assignee: nobody → pitti
importance: Undecided → Medium
status: Confirmed → In Progress
Revision history for this message
Thom May (thombot) wrote :

As far as I can tell, the upstream bug linked here is not the same thing as what the reporter is seeing. In fact, the last two comments on the upstream bugzilla are related to exactly the same error messages, and Ruediger points out that it's not the same bug.

Martin Pitt (pitti)
Changed in apache2:
assignee: pitti → nobody
status: In Progress → Unconfirmed
Revision history for this message
JB (jb-ubuntu1804) wrote :

Here the correct Bug Report about my problem -> http://issues.apache.org/bugzilla/show_bug.cgi?id=40029

They will not solve this problem for security reason! I hope that Ubuntu want to fix this problem.

Revision history for this message
Tollef Fog Heen (tfheen) wrote :

This will not be fixed in dapper; it's not a security vulnerability, nor does it make apache 2 unusable.

Changed in apache2:
status: Unconfirmed → Rejected
Revision history for this message
Tollef Fog Heen (tfheen) wrote :

This isn't a bug in apache2, but rather how MS abuses HTTP (with security-implications), so rejecting as per upstream.

Changed in apache2:
status: Unconfirmed → Rejected
Revision history for this message
Clay Perrine (clay-perrine) wrote :

So you are willing to piss off a lot of admins who use apache for their proxy server rather than Microsoft's ISA server because Microsoft "abuses" HTTP?

Is there not another way to fix the security hole without breaking the reverse proxy for this application?

Frankly.. this sounds like a pissing contest between the apache folks and Microsoft. And those of us who are trying to run a secure website are the losers.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.