
Apache problem, with a patchy solution...
Published: 18 June 2002 11:25 GMT
US Internet security institute Cert has warned of a serious flaw in the open source Apache web server software which is used to run more than half the world's websites.
According to Cert there is a vulnerability in the processing of large chunks of data in Apache versions 1.3 to 1.3.24 and 2.0 to 2.0.36. Depending on the version of Apache the security hole can either allow a hacker to run arbitrary code or cause a denial of service (DoS) attack.
However, Cert warns that patches for the hole will depend on what vendor you have bought your Apache web server software from. Some vendors have not yet patched the hole.
Cert has not made it clear at this time exactly who needs to be worried about the problem, although IBM has admitted its version of the software is affected.
In an advisory on its site Cert said: "Several sources have reported that this vulnerability can be used by intruders to execute arbitrary code on Windows platforms. Additionally, the Apache Software Foundation has reported that a similar attack may allow the execution of arbitrary code on 64-bit UNIX systems."
It said the advisory will be updated as soon as vendor-specific information becomes available: "Because the publication of this advisory was unexpectedly accelerated, statements from all of the affected vendors were not available at publication time."
Apache runs around two thirds of the world's websites, and is available to download free under an Open Source software licence. However, many commercial vendors bundle it in with other products - such as application servers - because of its popularity.
Microsoft's IIS web server, in which vulnerabilities were famously exploited last year by the Code Red and Nimda viruses, runs just 25 per cent of websites.
More help can be found here:
http://www.cert.org/advisories/CA-2002-17.html
We are looking for: - Strong, hands on technical coding experience with Java / J2EE technologies: Java, J2EE, JSP, JSR, EJB, XML, Web servers - ...
Potential for expanded responsibilities as the company growsExperience & Qualifications:Experience Qualifications/ SkillsRequired:3yrs+ Linux Admin ...
Strong, hands on technical experience with Java / J2EE technologies: Java, J2EE, JSP, EJB, XML, Web / web application servers - Apache, IIS, ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Seb Janacek Magic Mouse - Apple's best ever? Minority Report: After years of disappointment, one Mac lover has hope
Bethan Jones Can I use a netbook as my everyday work machine? Why silicon.com's sub editor is ditching her laptop for a sprightly mini-laptop