Results 1 to 2 of 2

Thread: Apache Updates Popular HTTP Server

  1. #1
    Join Date
    Apr 2003

    Apache Updates Popular HTTP Server

    The Apache Software Foundation and The Apache Server Project Friday issued its latest upgrade to the Apache HTTP Server 1.3 family.

  2. #2
    Senior Member
    Join Date
    Apr 2002

    Luckily I don't know anyone silly enough to want to run this thing on Winblowz... ;-)


    This version of Apache is principally a bug and security fix release. A partial summary of the bug fixes is given at the end of this document. A full listing of changes can be found in the CHANGES file. Of particular note is that 1.3.28 addresses and fixes 3 potential security issues:

    • CAN-2003-0460 (cve.mitre.org): Fix the rotatelogs support program on Win32 and OS/2 to ignore special control characters received over the pipe. Previously such characters could cause it to quit logging and exit. We would like to thank the Hitachi Incident Response team for their responsible disclosure of this issue.
    • VU#379828 : The server could crash when going into an infinite loop due to too many subsequent internal redirects and nested subrequests.
    • Eliminated leaks of several file descriptors to child processes, such as CGI scripts.

    \"Windows has detected that a gnat has farted in the general vicinity. You must reboot for changes to take affect. Reboot now?\"

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts