[20341] in bugtraq

home help back first fref pref prev next nref lref last post

OpenBSD 2.8patched Apache vuln!

daemon@ATHENA.MIT.EDU (zvz)
Fri Apr 20 05:05:46 2001

MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-ID:  <Pine.GSO.4.21.0104191424110.15421-100000@freenet.nether.net>
Date:         Thu, 19 Apr 2001 14:34:26 -0400
Reply-To: zvz <zvz@FREENET.NETHER.NET>
From: zvz <zvz@FREENET.NETHER.NET>
To: BUGTRAQ@SECURITYFOCUS.COM

Looks like we have patched versions of 2.8,
but on the mainstream of it (cvs),
the included apache version (usr.sbin/httpd) IS VULN
to the following bug:

http://www.securityfocus.com/vdb/bottom.html?vid=2503

Just GO and get the latest version of Apache, nomatter (I assume)
what OpenBSD ver you have, at least on the ones it is included by
default.

Just got confirmed on the tech@openbsd.org, thath only the CURRENT
is PATCHED(updated to 1.3.19).

Sure, I see that the OpenBSD is the best in terms of security, I
understand, that they are maybe short on people, I know that they work
for free, but still,
maybe the patch policy in not one of the best of it.

Regards
Zvz

home help back first fref pref prev next nref lref last post