UBB.Dev
Posted By: JustDave Apache webserver security anouncement... - 06/18/2002 7:38 PM
Just thought this would be of interest.

[]
Versions of the Apache web server up to and including 1.3.24 and 2.0 up to and including 2.0.36 contain a bug in the routines which deal with invalid requests which are encoded using chunked encoding. This bug can be triggered remotely by sending a carefully crafted invalid request. This functionality is enabled by default.



Read more here: Full Story


Posted By: WrÅith Re: Apache webserver security anouncement... - 06/19/2002 1:28 AM
From the sound of it, it appears to be a Windows-only problem; however, there is mention of UNIX later on. Is this a problem for Unix-based systems?
Posted By: JustDave Re: Apache webserver security anouncement... - 06/19/2002 5:00 AM
As I understand it, all Apache servers in the 1.x and 2.x series are affected to some extent with windows being more prevalent.
Posted By: Ian_W Re: Apache webserver security anouncement... - 06/19/2002 1:57 PM
My understanding is that Unix 64bit and Windows are affected but Unix 32 bit are not.

Ian
© UBB.Developers