Showing posts with label apache. Show all posts
Showing posts with label apache. Show all posts

Maintenance of Apache web server 2.0 discontinued

With the recent release of Apache web server version 2.0.65, the Apache project has discontinued the maintenance of the 2.0 version branch. The developers have urged users to migrate to current version series 2.2 or 2.4 editions as soon as possible; version 2.4 was released in February 2012.

http://www.h-online.com/security/news/item/Maintenance-of-Apache-web-server-2-0-discontinued-1917444.html
Maintenance of Apache web server

Maintenance of Apache web server 2.0 discontinued

With the recent release of Apache web server version 2.0.65, the Apache project has discontinued the maintenance of the 2.0 version branch. The developers have urged users to migrate to current version series 2.2 or 2.4 editions as soon as possible; version 2.4 was released in February 2012.

http://www.h-online.com/security/news/item/Maintenance-of-Apache-web-server-2-0-discontinued-1917444.html
Maintenance of Apache web server 2.0 discontinued
Version 2.0 of the web server first became available for general use eleven years ago. Among the issues that have been fixed in this final release are six CVE-numbered security holes – including a bug in the logging feature that potentially allowed attackers to gain control of the server. However, the developers of the web server that is also known as "httpd" or "Apache HTTP Server" point out that it remains possible to exhaust all memory using a carefully crafted .htaccess rule. The issue will remain unresolved in version series 2.0; version 2.2.25, which was released in parallel with 2.0.65, has been modified to minimise this risk. This version also fixes the previously mentioned security hole in the logging feature.

Botnet using Plesk vulnerability and takedown

Parallels Plesk
Today while investigating the Plesk/Apache Remote Code Execution vulnerability disclosed by Kingcope, we uncovered what appeared to be a sizeable botnet leveraging this vulnerability to infect webservers with a malicious IRC bot written in Perl; a loosely modified version of a publicly known tool.

A large list of hosts believed to be infected was generated from the data gathered, and probed in an automated fashion for vulnerable Plesk installations. Over 900 hosts attempting to connect were running vulnerable Plesk installations, confirming our suspicion that the Plesk exploit was how this malware was spreading; based on our estimates, about 40 hosts were being infected an hour, which we found intolerable.

Source

Multiple XSS in Apache modules

Apache HTTP Server
Cross-site scripting (XSS) flaws were found in the mod_proxy_balancer module's manager web interface. If a remote attacker could trick a user, who was logged into the manager web interface, into visiting a specially-crafted URL, it would lead to arbitrary web script execution in the context of the user's manager interface session. (CVE-2012-4558)