Apache Patches Security Flaw
Vulnerability could allow denial of service attacks.
Paul Roberts, IDG News Service
A new release of the popular Apache 2.0 Web server fixes a number of security vulnerabilities including an as-yet-undisclosed flaw that could be used to launch a denial of service attack against machines running Apache, according to information released by the Apache Software Foundation.
The new release, version 2.0.45, is intended "principally as a security and bug fix release," according to the ASF.
First and foremost on the list of fixed vulnerabilities was a security hole discovered by David Endler, director of Technical Intelligence at security intelligence firm iDefense of Reston, Virginia.
Details on the vulnerability discovered by Endler were not disclosed, but Apache 2.0 users were encouraged to upgrade.
Endler will publish a report on the vulnerability on April 7, according to the ASF.
Other, lower priority security leaks and bug fixes were also included in the 2.0.45 release.
Another Fix Needed
However, a known DOS vulnerability that affects those systems running Apache on the OS/2 platform remains open. The latest Apache version was "too important" to delay release until the OS/2 fix could be included, the ASF said.
OS/2 users will have to wait for the release of 2.0.46 to get a fix for that problem, the ASF said.
The decision by the ASF and iDefense to withhold information on a major vulnerability for a week following the release of a patch stands in contrast to prior revelations about security holes in the Apache software.
In August, security company PivX Solutions LLC released information on a major vulnerability shortly after the ASF published a software patch to fix the problem.
Users of all prior versions of Apache were encouraged to update to the latest release.
- Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
- Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
- Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
- Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
- Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?
Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
Solve Tech Issues Fast
SMB Networking Center
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Antivirus Software
Norton AntiVirus 2009 (Full Product)Price: $14.84
VirusScan Plus 2009 - 3-User (Full Product)Price: $4.00
Anti-Virus 2009 (Full Product)Price: $17.85
VirusScan Plus 2009 (Full Product)Price: $4.00
McAfee VirusScan Plus 2008 (Full Product)Price: $3.23
Anti-Virus Pro 2009 (Full Product)Price: $5.88
- 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
- Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.


