Bug 28577

Summary: apache2.0.49 with mod_ssl openssl crash when special falsh file
Product: Apache httpd-2 Reporter: sanry williams <sanry>
Component: mod_sslAssignee: Apache HTTPD Bugs Mailing List <bugs>
Status: CLOSED DUPLICATE    
Severity: critical    
Priority: P3    
Version: 2.0.49   
Target Milestone: ---   
Hardware: PC   
OS: Linux   
URL: http://www.todayisp.com

Description sanry williams 2004-04-25 02:50:14 UTC
I change openssl version many times, both openssl0.97d or openssl0.96m.
I use vhost , mpm=worker and no php supported when test.
In ssl.conf  I change RC4-MD5 to RC4-SHA but apache still crash 
and I change SSLMutex from default  to pthread  too,
but still crash .
The bad falsh swf can found at 
http://www.todayisp.com/email/images/promail2004.swf 

,but you 'd better save as the whole page http://todayisp.com/email/ to test


cat  error_log
[Sun Apr 25 10:38:07 2004] [warn] pid file /usr/local/apache2/logs/httpd.pid 
overwritten -- Unclean shutdown of previous Apache run?
[Sun Apr 25 10:38:07 2004] [notice] Apache/2.0.49 (Unix) mod_ssl/2.0.49 
OpenSSL/0.9.6m configured -- resuming normal operations
[Sun Apr 25 10:38:26 2004] [notice] child pid 19295 exit signal Segmentation 
fault (11)

cat ssl_request_log
25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /images/arrowgreen.gif HTTP/1.1" 330
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /email2/images/promail_logo.gif HTTP/1.1" 4421
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /news/images/new_3.gif HTTP/1.1" 330
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /images/v6/shopping_cart.gif HTTP/1.1" 336
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /product/img/pro300.jpg HTTP/1.1" 331
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /product/img/pro500.jpg HTTP/1.1" 331
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /product/img/com1000.jpg HTTP/1.1" 332
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /product/img/com2500.jpg HTTP/1.1" 332
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /product/img/vps5000.jpg HTTP/1.1" 332
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /product/img/vps9000.jpg HTTP/1.1" 332
[25/Apr/2004:10:38:25 +0800] 219.235.211.237 SSLv3 RC4-
SHA "GET /email2/images/promail2004.swf HTTP/1.1" 13723
Comment 1 Paul Querna 2004-04-29 01:29:31 UTC
Can you please try to use gdb and get a backtrace of this crash?

There are intructions for doing this here:
http://httpd.apache.org/dev/debugging.html

Thanks, 

-Paul Querna
Comment 2 Joe Orton 2004-05-25 19:13:54 UTC
mod_ssl crash in 2.0.49 => suspect bug 27945.

*** This bug has been marked as a duplicate of 27945 ***