Apache Patches Security Flaw
Vulnerability could allow denial of service attacks.
Paul Roberts, IDG News Service
A new release of the popular Apache 2.0 Web server fixes a number of security vulnerabilities including an as-yet-undisclosed flaw that could be used to launch a denial of service attack against machines running Apache, according to information released by the Apache Software Foundation.
The new release, version 2.0.45, is intended "principally as a security and bug fix release," according to the ASF.
First and foremost on the list of fixed vulnerabilities was a security hole discovered by David Endler, director of Technical Intelligence at security intelligence firm iDefense of Reston, Virginia.
Details on the vulnerability discovered by Endler were not disclosed, but Apache 2.0 users were encouraged to upgrade.
Endler will publish a report on the vulnerability on April 7, according to the ASF.
Other, lower priority security leaks and bug fixes were also included in the 2.0.45 release.
Another Fix Needed
However, a known DOS vulnerability that affects those systems running Apache on the OS/2 platform remains open. The latest Apache version was "too important" to delay release until the OS/2 fix could be included, the ASF said.
OS/2 users will have to wait for the release of 2.0.46 to get a fix for that problem, the ASF said.
The decision by the ASF and iDefense to withhold information on a major vulnerability for a week following the release of a patch stands in contrast to prior revelations about security holes in the Apache software.
In August, security company PivX Solutions LLC released information on a major vulnerability shortly after the ASF published a software patch to fix the problem.
Users of all prior versions of Apache were encouraged to update to the latest release.
Save on Printing Costs
Mobile Computing
Dell Fast Track
-
Free Next Day Business Shipping on Dell's Most Popular Systems
Over 35% off Dell’s most popular systems. Delivered in 48 hours with free next business day shipping! Ends 12/22 at 3 PM CST
People who read this also read:
Best Prices on System Utilities
Parallels Desktop 4.0 for Mac (Full Product)Price: $49.99
Norton Partition Magic 8.0 Rev1RetailPrice: $49.99
2009 ProfessionalPrice: $29.00
Disk Director Suite 10.0 (Full Product)Price: $24.76
Fusion 3Price: $69.94
Prosoft Drive Genius 2Price: $49.88
- Acer Laptop Center Forget the Mouse...check out the next generation multi-gesture touch screen technology from Acer.
- Dell Shopping Center Check out great deals from Dell!
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage










