Blog-N-Play.com
Anytime a feature of a framework gives me something for free that I don't need to manually implement I'm a happy camper. One such feature of ASP.NET MVC 2 is jQuery client-side validation. The
Read Digital Edition


ADS BY GOOGLE
Most Read This Week
Top Three Links You Must Click On


Apache group issues update, warns of security hole
Apache, 2.0.46 is a security and bug fix

(IDG News Service) — For the second time in as many months, the Apache Software Foundation released an updated version of the popular open source Web server software, only to warn users of a critical security hole in previous versions of the software that the update patches.

The new version of Apache, 2.0.46, was described as "principally a security and bug fix release" in a bulletin released by the open source organization Wednesday.

Among those fixes is a patch for a security hole in the mod_dav module that could be exploited remotely, causing an Apache Web server process to crash, according to the bulletin.

Mod_dav is an open source module that provides WebDAV (World Wide Web Distributed Authoring and Versioning) protocol support for the Apache Web server.

WebDAV is a set of extensions to HTTP (Hypertext Transfer Protocol) that allows users to edit and manage files on remote Web servers. The protocol is designed to create interoperable, collaborative applications that facilitate geographically-dispersed "virtual" software development teams.

Few details were available regarding the mod_dav vulnerability, which was first discovered and reported to the Foundation by a researcher at security firm iDefense Inc.

Further details regarding the problem will be published on Friday, the bulletin said.

In March, Microsoft released a patch for a security hole in a core Windows component used to handle an unchecked buffer in a Windows 2000 component used to handle the WebDAV protocol. That flaw, which has already been exploited by hackers, could enable an attacker to cause a buffer overflow on the machine running Internet Information Server, according to the Microsoft Security bulletin MS03-007.

A second fix is for a denial-of-service vulnerability affecting Apache's authentication module.

By exploiting a bug in configuration scripts used by a function for password validation, attackers could launch remote denial of service attacks that would cause valid user names and passwords to be rejected, the bulletin said.

The vulnerabilities affect versions of Apache ranging from 2.0.37 up to the most recent release, 2.0.45, which came out in April.

That latest version was also released in response to a heretofore unknown critical security flaw which, like the mod_dav vulnerability, was discovered by iDefense and described in detail at a later date.

As with its last software update, the Apache Software Foundation said that 2.0.46 was the "best version of Apache available" and recommended that users of prior Apache versions upgrade.

About Paul Roberts
Paul Roberts is a Boston correspondent for the IDG News Service, a Linux.SYS-CON.com affiliate.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

  Subscribe to our RSS feeds now and receive the next article instantly!
In It? Reprint It! Contact advertising(at)sys-con.com to order your reprints!
Subscribe to the World's Most Powerful Newsletters
Linux Links You Must Click On !

Lo Ultimo
Bottega Veneta y Coty Inc., un líder en la industria de la belleza global, han anunciado hoy la form...
La embajadora mundial de AvonReese Witherspoon ha sido anfitriona de una fiesta del té exclusiva par...

GameStop Corp. (NYSE:GME), la empresa minorista de software de videojuegos y entret...

Un estudio online publicado esta semana en Science ha demostrado que SPC3649, una revolucionaria ter...
Microsoft Corp. ha anunciado hoy una oleada de informes voluntarios - más de 150.000 en los dos últi...
ADS BY GOOGLE
Some people say “oh, you’re dual licensing like MySQL. So does that mean that I get to use it and no...
Michael Bell, founder of Methodologies Corporation, the leading service-oriented modeling company, a...
Dune Networks' Highly Scalable Switch Fabric Technology Expands Broadcom's Product Portfolio for Dat...
M86 Security, a leading global provider of Web and messaging security products, released Predictions...
JetBrains, creators of intelligent, productivity-enhancing development tools, announced the public a...
Researchers from Intel Labs demonstrated an experimental, 48-core Intel processor, or “single-chip c...
The irony is that Oracle has advanced MySQL, lost money in the process, and helped its competitors -...
The founders of Crystal Reports and veterans of Microsoft, Symmetrics and Business Objects have laun...
I first met Mark Fishburn at the Convergence Technology Council (CTC) in Calabasas, California. Mark...
Concerns about the security of cloud computing environments top the list of reasons for firms not be...
WSO2, the open source SOA company, today announced the launch of the WSO2 Cloud Platform. Available ...
Red Hat Enterprise Linux running on Intel® processor-based servers helps your customers reduce TCO, ...
Now is the time to examine the TCO migrating from Unix to the more cost-effective open systems platf...
Making the right choices around technology is critical to the success of your business. Finding out ...
Dell is transferring ownership of its new factory in Poland over to contract manufacturer Foxconn Te...
Michael Donnelly, Group Director Worldwide Interactive Marketing, Coca-Cola and Michael Buck Global ...
To address this need, increasing numbers of healthcare organizations are evaluating enterprise imagi...
Some great news came out of Sun Microsystems yesterday with the release of VirtualBox 3.1.o. This is...
Thales announces SafeSign Mobile Authentication which enables strong authentication using a mobile d...
IGEL's Linux firmware now supports popular touchscreen monitors, including the LG L1730SF Monitor an...