Apache 2.0.52 Released 16
roly writes "Not long after 2.0.51 was released, Apache 2.0.52 has come out. It's primarily a bugfix release, fixing one security flaw that was introduced in 2.0.51. See the release announcement, and the changelog. Download it from a mirror."
Category (Score:1, Insightful)
Apache 2.0.52 fixes 2.0.51 security regression (Score:4, Informative)
Re:Apache 2.0.52 fixes 2.0.51 security regression (Score:2, Insightful)
I'm running 1.3.x still and not sure whether to be glad it's not affected or worried it might be affected but noone notices.
Re:Apache 2.0.52 fixes 2.0.51 security regression (Score:4, Informative)
Many folks still run 1.3, and holes in that version tend to get fixed.
Re:Apache 2.0.52 fixes 2.0.51 security regression (Score:2, Informative)
http://www.computec.ch/projekte/atk/plugins/plugin slist/Apache%20prior%201.3.32%20htpasswd%20buffer% 20overflow.plugin.html [computec.ch]
Apache security documentation (Score:3, Informative)
http://www.cgisecurity.com/webservers/apache/ [cgisecurity.com]
patch vs. upgrade (Score:1)
Overall, great job by the Apache team and those that support them!
Re:patch vs. upgrade (Score:3, Interesting)
I frequently hack infrastructure software (like sendmail, bind and apache) to report incorrect version numbers, because that way the crackers always start out by trying attacks that don't work and are easily detected.
Every time I see some buffoon trying an old sendmail trick I blackhole their IP at the edge router. I hope to eventually set up a tarpit and mire the losers in that, but for now I just discard th
question - slightly offtopic (Score:1)
can i throttle to montly amount of traffic per virtual site?
there was a mod in apache 1.x but i know none for 2.x