main

Apache Updates Web Server Software (Again)

Daniel Fleshbourne   on 29 May 2003 - 07:58 · 11 comments & 771 views

Advertisement (Why?)
For the second time in as many months, the Apache Software Foundation released an updated version of the popular open-source Web server software, only to warn users of a critical security hole in previous versions of the software that the update patches. The new version of Apache, 2.0.46, was described as "principally a security and bug fix release" in a bulletin released by the open-source organization Wednesday. Among those fixes is a patch for a security hole in the mod_dav module that could be exploited remotely, causing an Apache Web server process to crash, according to the bulletin.

Mod_dav is an open-source module that provides WebDAV (World Wide Web Distributed Authoring and Versioning) protocol support for the Apache Web server. WebDAV is a set of extensions to Hypertext Transfer Protocol that allows users to edit and manage files on remote Web servers. The protocol is designed to create interoperable, collaborative applications that facilitate geographically dispersed "virtual" software development teams.

View: The full story
News source: pcworld.com


Mixed Reviews

It is safe to assume that not everyone is eager for Huang's guide to home modification of the XBox to gain a wide audience when it becomes available on May 27th.

XBox manufacturer Microsoft, along with Nintendo and Sony (NYSE: SNE) , has filed a lawsuit against Lik-Sang, a Hong Kong-based gaming-equipment company that sold mod chips, a device used to play copied games. The company was temporarily shut down and no longer sells the devices.

Faring even worse was David Rocci, who was sentenced to five months in prison and levied a stiff fine for running a Web site that sold mod chips and helped gamers find unauthorized copies of Xbox games to run on their modified boxes.

Post a comment · Send to friend Comments · There are 11 additional comments
#1 edgrale on 29 May 2003 - 08:59
They make it sound like releasing a new version with bug fixes is a BAD thing...
#2 kemical on 29 May 2003 - 11:47
yea this happens nightly in some cases, people in the *nix world are pretty accustomed to patch releases and just about every piece of software is in beta
#3 Rathamon on 29 May 2003 - 13:10
hmm . what I want to know is how does this affect my 1.3.x servers?
Havent had the courage to step into the brave new 2.x world on a production box just yet
#4 antareus on 29 May 2003 - 13:10
Ironic, MS doesn't have a good track record with DAV either.

Buffer overflows are so 1998 you'd think people would learn to dodge them by now. (Speaking as a programmer here)
#5 zivan56 on 29 May 2003 - 14:01
I'm sticking to 1.3.x
(1 reply) #6 mr_da3m0n on 29 May 2003 - 15:28
Doesn't afftect the 1.3.x tree right?
#6.1 edgrale on 29 May 2003 - 15:31
if it would they would have released a new version.
(1 reply) #7 goodness0001 on 29 May 2003 - 16:19
it seems like linux related software is having as many security updates as MS
#7.1 zivan56 on 30 May 2003 - 00:03
Apache is not only Linux software, it runs on quite a few OS's.
#8 Germano on 29 May 2003 - 17:33
Isn't this Software news?
#9 Germano on 31 May 2003 - 17:24
http://www.neowin.net/comments.php?category=software&id=11446

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)