- Recommend:
- 0 Comments
Apache Patches Security Flaw
Vulnerability could allow denial of service attacks.
A new release of the popular Apache 2.0 Web server fixes a number of security vulnerabilities including an as-yet-undisclosed flaw that could be used to launch a denial of service attack against machines running Apache, according to information released by the Apache Software Foundation.
The new release, version 2.0.45, is intended "principally as a security and bug fix release," according to the ASF.
First and foremost on the list of fixed vulnerabilities was a security hole discovered by David Endler, director of Technical Intelligence at security intelligence firm iDefense of Reston, Virginia.
Details on the vulnerability discovered by Endler were not disclosed, but Apache 2.0 users were encouraged to upgrade.
Endler will publish a report on the vulnerability on April 7, according to the ASF.
Other, lower priority security leaks and bug fixes were also included in the 2.0.45 release.
Another Fix Needed
However, a known DOS vulnerability that affects those systems running Apache on the OS/2 platform remains open. The latest Apache version was "too important" to delay release until the OS/2 fix could be included, the ASF said.
OS/2 users will have to wait for the release of 2.0.46 to get a fix for that problem, the ASF said.
The decision by the ASF and iDefense to withhold information on a major vulnerability for a week following the release of a patch stands in contrast to prior revelations about security holes in the Apache software.
In August, security company PivX Solutions LLC released information on a major vulnerability shortly after the ASF published a software patch to fix the problem.
Users of all prior versions of Apache were encouraged to update to the latest release.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Bugs and Fixes: Adobe gives Users Privacy Controls; Skype Patches Extremely Dangerous Vulnerability
- A Rivalry Emerges As Apache Asserts OpenOffice Plans
- Bugs and Fixes: Microsoft Patches 34 Vulnerabilities
- Patch Tuesday Fixes Dangerous Flaws with Exploits Imminent
- Google Patches Security Holes in Chrome Browser
- Microsoft Releases Security Update for IE9
- Microsoft Announces Coordinated Vulnerability Disclosure Procedures And First Two Vulnerability Advisories
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.


















