Apache HTTP Server 2.2.3 Released

Roel van Bueren's picture
Submitted by Roel van Bueren on July 31, 2006 - 2:53pm.

Most Novell shops use Apache 2.0 on their GroupWise WebAccess, iFolder, NetStorage, VirtualOffice and iManager servers. Now the Apache Software Foundation and The Apache HTTP Server Project have released version 2.2.3 of the Apache HTTP Server ("Apache"). This version of Apache is principally a bug and security fix release. The following potential security flaws are addressed. Depending on the manner in which your Apache HTTP Server was compiled, this software defect may result in a vulnerability which, in combination with certain types of Rewrite rules in the web server configuration files, could be triggered remotely. For vulnerable builds, the nature of the vulnerability can be denial of service (crashing of web server processes) or potentially allow arbitrary code execution. This issue has been rated as having important security impact by the Apache HTTP Server Security Team. This flaw does not affect a default installation of Apache HTTP Server. Users who do not use, or have not enabled, the Rewrite module mod_rewrite are not affected by this issue. Users who do, should upgrade to this new 2.2.3 version. More information in the Apache 2.2.3 Release Notes. Apache 2.2.3 for e.g. NetWare, Linux and Windows can be downloaded here.

Categories: