March 21, 2010
Hot Topics:

Apache 2.2.12

Fix a potential Denial-of-Service attack against mod_deflate or other modules, by forcing the server to consume CPU time in compressing a large file after a client disconnects;
prevent the "Includes" Option from being enabled in an .htaccess file if the AllowOverride restrictions do not permit it;
fixed a potential Denial-of-Service attack against mod_proxy in a reverse proxy configuration, where a remote attacker can force a proxy process to consume CPU time indefinitely;
avoid delivering content from a previous request which failed to send a request body;
updated the bundled copy of the APR-util library has been, fixing three different security issues which may affect particular configurations and third-party modules;
fixed potential segfault when handling back references on an empty SSI variable

Release Date: Jul 31, 2009

Partners

  • Partner With Us














More on ServerWatch