[horde] Groupware: Apache says "anary mismatch on efree() - heap overflow detected"

Chuck Hagenbuch chuck at horde.org
Thu Jan 17 01:54:39 UTC 2008


Quoting Oskar Eyb <oskar-horde at eyb.de>:

> Jan Schneider schrieb am 17.01.2008 01:16:
>>> [Wed Jan 16 19:47:43 2008] [error] ALERT - canary mismatch on efree() -
>>> heap overflow detected (attacker '88.67.25.231', file
>>> '/var/www/htdocs/groupware/index.php')
>>
>> Disable Suhosin.
>
> You dont think its maybe better to fix the code instead?

The problem is in suhosin, or perhaps in PHP, but not in Horde - efree  
isn't a PHP function, it's a C function.

-chuck


More information about the horde mailing list