Slashdot Log In
Apache 2.0.48 Released
Posted by
CowboyNeal
on Sat Nov 01, 2003 07:49 PM
from the hitting-the-streets dept.
from the hitting-the-streets dept.
Gruturo writes "Busy week for the Apache software foundation:
After 1.3.29, version 2 gets an update as well with 2.0.48, which mainly fixes these two security vulnerabilities.
As usual, using a mirror is recommended." The official announcement lists several changes as well.
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Apache security documentation (Score:3, Informative)
http://www.cgisecurity.com/webservers/apache/ [cgisecurity.com]
RedHat Fedora coming out on Monday will have this? (Score:3, Informative)
Time to upgrade my Apple ][ server. (Score:3, Funny)
Hmmm... (Score:3, Funny)
Re:Hmmm... (Score:4, Funny)
It annoys me that I have to download the full dupe at every point release. Can't they post incremental patches for the article and the replies?
Parent
Re:Hmmm... (Score:2)
Re:Hmmm... (Score:3, Funny)
Re:Hmmm... (Score:1)
Re:Hmmm... (Score:1)
I tried? Dang. There is no try...
Then better mod me sideways, before my posting makes somebody cry.
Re:Hmmm... (Score:1)
I have a speech impediment, you insensitive clod!
Re:Hmmm... (Score:2, Funny)
Re:Hmmm... (Score:2, Insightful)
OMG YES YES YES! (Score:5, Funny)
This is the defining moment of my life. I have been continually pressing the "refresh" button since the story about 2.0.47 being released. Now all my hard work has paid off.
2.0.48 is released at last!
One question: (Score:1, Funny)
Re:OMG YES YES YES! (Score:4, Funny)
Not only do you need a life, you need to get better at not having one!
Parent
Logging bug (Score:5, Informative)
I looked at my logs and determined that a couple AOL users were trying to get a rather large file
aca9bd40.ipt.aol.com 655 6689 1004 310
acc4e74f.ipt.aol.com 1014 5412 521 148
ac8bd972.ipt.aol.com 140 1565 534 745
Requests MB KB Bytes. All that transfer supposedly happened in about a day.
I notified bug-track but apparently such a simple problem (which doesn't exist in the 1.3.x line) isn't worth addressing.
After all, who actually uses the Apache 2.0.x logs to monitor transfer? Hopefully not any hosting companies because the customers are going to get royally screwed.
Ben
Re:Logging bug (Score:2, Flamebait)
Re:Logging bug (Score:2)
Can we get past these comments about "fixing it yourself"? Or is this just the default customer service coming out these days?
I do thank you for not Karma whoring by posting as AC.
"Fix it yourself" (Score:2)
Especially considering someone did take the time to write a logging module that works and Apache still refuses to make it the st
Re:Logging bug (Score:5, Informative)
Seems to me that they do see this as a problem worth addressing; they already have a fix.
Parent
Workaround, not a fix (Score:2)
Most web-site owners are more interested in running their business than dicking around with source co
Re:Workaround, not a fix (Score:2)
Re:In other words, yet another OSS bug? (Score:1)
10 bucks (Score:1, Offtopic)
Netcraft stats for Apache (Score:5, Interesting)
the new netcraft stats are posted [netcraft.com].
apache just keeps stealing more market share-
Re:Netcraft stats for Apache (Score:2)
At no point in history has Apache ever had less marketshare than Microsoft's webserver.
Apache 2.0 (Score:3, Interesting)
Re:Apache 2.0 (Score:5, Informative)
I've seen bandwith drop on websites drop from 20-80% depending on how much content is non-compressible (like graphics).
Parent
Re:Apache 2.0 (Score:3, Interesting)
mod_perl is a real showstopper for me. I'd love to upgrade to Apace2.x but I really need mod_perl to function properly and it isn't ready so I'm sticking with 1.3 for now.
Does anyone know the status of mod_perl? Should I try to lessen my dependency on it? Is 2.0 worth the upgrade even if I have to rewrite my app?
Re:Apache 2.0 (Score:2)
1.3 branch (Score:2)
Re:1.3 branch (Score:3, Informative)
Re:1.3 branch (Score:4, Informative)
The problem isn't Apache itself but the open source modules that help make Apache the most useful webserver out there. Widely used projects like mod_perl and mod_php have only recentlyy released versions of these that work properly with Apache 2 and even these are still labeled betas.
Additionally, most competent sysadmins won't mess with what isn't broken, so their server farms running 1.3 are going to continue running 1.3 for a while yet.
Parent
Re:A step in the right direction (Score:3, Insightful)
Yea, I know.. ihbt..
Re:A step in the right direction (Score:5, Informative)
Tomcat is open source; it's one of the Jakarta projects.
compared to Oracle's WebSphere
IBM make WebSphere, not Oracle.
If Ximian would only release the
Microsoft makes the
Parent
Re:A step in the right direction (Score:1)
Tomcat is Apache Foundation and Free(tm).
LocalDirector is Cisco.
Besides those minor error and the jibberish the +1 Interesting might be sensible?
Re:A step in the right direction (Score:1)
huh? Microsoft Internet Security and Acceleration Server? The one all the dweebs put in front of Exchange when management's looking the other way? That's not an application server, it's a proxy/firewall whose chief function is to generate revenue for Microsoft while providing zero real functionality.
the Apache team outdid themselves by providing a nice API that integrates nicely with most the commercial application servers such as Tomcat...
How
Re:What??! (Score:2)
side note. I love this type m keyboard!!!
Re:Debian (Score:2)
Re:Debian (Score:1)
Ok, good, I was curious whether or not they were actually distributing security updates, which is why I was starting to worry.
Re:Debian (Score:1)
Re:Debian (Score:1)
Why not jsut download it and install it yourself?
Re:Debian (Score:4, Interesting)
So. Untinstall the deb, download it, compile it, install it, and get it working. It's no harder to configure, and you're free of package tyranny.
Parent
Re:Debian (Score:2)
Link above logs you out (Score:1)
Re:If it "works", why did it need a patch? (Score:1)
Thank you! Now where are my mod points?...
Re:If it "works", why did it need a patch? (Score:2)
Microsoft has VERY LITTLE (compared to Apache) market share, yet it's been actually exploited MUCH MUCH more.
Another point about Apache is that it's open source (we can search the source and find buffer overflow succeptible code, fix it, etc.,) while with Microsoft or others, once they fix a bug, you have no idea how bad their source code it.
Also, fixing 2 bugs in this many months is actual
Re:American Indians (Score:1)
Re:Cock-smoking? (Score:2, Funny)
Yah, as if anyone's going to let you take a lighter to their cock...sheesh...
Re:Don't forget... (Score:1)