Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

user friendly

  linux-magazine.com » Online » News » Apache Closes Down Vulnerabilities  

Print this page. Recommend
Slashdot it! Delicious Digg

Apache Closes Down Vulnerabilities

No less than five vulnerabilities were eradicated by the release of a new version of the Apache Web server.

Release 2.2.6 removes five partly critical security holes. Four of them are also closed by the latest 2.0 branch release, version 2.0.61. According to the Apache Foundation's release notes, vulnerabilities were removed in the "mod_proxy" and "mod_cache" modules. Attackers had previously been able to crash servers by targeted requests leading to a Denial-of-Service (DoS) attack.

A cross site scripting bug discovered by Stefan Esser – the initiator of the "Month of PHP Bugs" – is also a thing of the past. The fourth bug that affected both versions resulted in a DoS vulnerability in the Prefork-MPM module. The bug in the "mod_mem_cache" module only occurs in the 2.2 series. The vulnerability gave attackers the ability to read headers from prior connections in some circumstances.

The developers advise server administrators to switch to one of the new versions as soon as possible. The versions are available, as always, from the project's mirror servers. Besides fixing various vulnerabilities, the patches also include a number of bugfixes.

(Jan Rähm)

Comments


Print this page. Recommend
Slashdot it! Delicious Digg
Related Articles
Security Bugs in Kernel and Rsync
Samba Shuts Down Vulnerability in AD Interface
Script Error Opens up Security Hole in Xen 3.0.3
EnGarde Secure Linux Community 3.0.18 Released
Kernel 2.6.25: 64 Bit Systems At Risk
Security Bug in Legacy Unix HP-UX
Wherever you go...

...Linux Magazine goes with you!

Check out the advantages of a Digital Subscription:

  • Access articles by downloading PDFs,
  • find the Linux solutions you need with an easy keyword search,
  • maintain your own paperless archive...

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2008 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux-Nachrichten] [Linux Events]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Darmowe Programy Poland] [Open Source DVD Poland] [Linux Magazin Romania]
International: [Linux Magazine Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]