Apache Closes Down Vulnerabilities
No less than five vulnerabilities were eradicated by the release of a new version of the Apache Web server.
Release 2.2.6 removes five partly critical security holes. Four of them are also closed by the latest 2.0 branch release, version 2.0.61. According to the Apache Foundation's release notes, vulnerabilities were removed in the "mod_proxy" and "mod_cache" modules. Attackers had previously been able to crash servers by targeted requests leading to a Denial-of-Service (DoS) attack.
A cross site scripting bug discovered by Stefan Esser – the initiator of the "Month of PHP Bugs" – is also a thing of the past. The fourth bug that affected both versions resulted in a DoS vulnerability in the Prefork-MPM module. The bug in the "mod_mem_cache" module only occurs in the 2.2 series. The vulnerability gave attackers the ability to read headers from prior connections in some circumstances.
The developers advise server administrators to switch to one of the new versions as soon as possible. The versions are available, as always, from the project's mirror servers. Besides fixing various vulnerabilities, the patches also include a number of bugfixes.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Digital Autonomy
• How the Fediverse Found Parts for Its Platforms
• The Answer Was Already on the Shelf
• Changing the Chip Industry: How Public Investment Has Grown Open Silicon
• United Nations Open Source Portal Goes Live
• EU Open Source Strategy Plays Key Role in Tech Sovereignty Package
• France Says “Au Revoir” to Microsoft
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Office 365 Available for Testing on Linux via Bottles
Linux users can now test the official Office 365, thanks to Mirko Brombin's work on Bottles.
-
Dutch Government Turns to Open Source for Digital Sovereignty
Following in the footsteps of other European countries, the Netherlands is looking to increase its sovereign digital infrastructure with open source software.
-
Linux May Soon Work on Snapdragon X2-Based PCs
If you're thinking about buying a Snapdragon X2-based desktop or laptop, Linux may soon be an option.
-
KDE for People Initiative Calls for AI Ban in Plasma
A new community of KDE wants the project to adopt a strict no-AI policy for KDE Plasma.
-
KDE Sets Ambitious Goals for 2026 and Beyond
KDE Connect reveals the goals for the Linux desktop darling, with one of those goals long overdue.
-
It’s Time to Test Fedora 45 Beta
Fedora 45 beta has been released with updated Gnome, KDE Plasma, and kernel.
-
Ubuntu Stonking Stingray Gets Even Rustier
Ubuntu 26.10 has completed its migration to the Rust-based coreutils.
-
AI Fixes Linux Bottlenecks Using “Hideous” Code
A Linux developer used AI to fix bottlenecks that caused problems when building the kernel. The resulting AI-generated code needed a lot of work.
-
Advanced Video Coding Still Under Patent
Brazilian patent BRPI0109962B1 has expired, which means that DivX and Xvid are no longer problematic for Linux, but it doesn’t mean that video is all of a sudden fully unleashed.
-
2,000 Vulnerabilities per Linux Release
Thanks to AI bug hunters, the Linux kernel is seeing record numbers of vulnerabilities, and it's overwhelming developers.
