设为首页收藏本站

LUPA开源社区

 找回密码
 注册
文章 帖子 博客

Apache 1.3 最终版发布

2010-2-3 16:33| 发布者: walkerxk| 查看: 733| 评论: 1

Apache 1.3 发布了该系列的最新发布版1.3.42,和1.3.41相比,该版本修正了若干安全/稳定性问题。 官方已经决定终结 Apache 1.3 的生命周期,1.3.42 版本将是该系列的最后一个有版本号的发布,将来官方会以补丁形式提供重要安全更新。 据称,Apache 1.3 系列曾是被最多使用的http服务器版本。下面是通告全文:
   The Apache Software Foundation and the Apache HTTP Server Project are
pleased to announce the release of version 1.3.42 of the Apache HTTP
Server ("Apache"). This release is intended as the final release of
version 1.3 of the Apache HTTP Server, which has reached end of life
status.

There will be no more full releases of Apache HTTP Server 1.3.
However, critical security updates may be made available from the
following website:

http://www.apache.org/dist/httpd/patches/

Our thanks go to everyone who has helped make Apache HTTP Server 1.3
the most successful, and most used, webserver software on the planet!

This Announcement notes the significant changes in
1.3.42 as compared to 1.3.41.

This version of Apache is is principally a bug and security fix release.
The following moderate security flaw has been addressed:

* CVE-2010-0010 (cve.mitre.org)
mod_proxy: Prevent chunk-size integer overflow on platforms
where sizeof(int) < sizeof(long). Reported by Adam Zabrocki.

Please see the CHANGES_1.3.42 file in this directory for a full list
of changes for this version.

Apache 1.3.42 is the final stable release of the Apache 1.3 family. We
strongly recommend that users of all earlier versions, including 1.3
family releases, upgrade to to the current 2.2 version as soon as possible.
For information about how to upgrade, please see the documentation:

http://httpd.apache.org/docs/2.2/upgrading.html

Apache 1.3.42 is available for download from

http://httpd.apache.org/download.cgi

This service utilizes the network of mirrors listed at:

http://www.apache.org/mirrors/

Binary distributions may be available for your specific platform from

http://www.apache.org/dist/httpd/binaries/

Binaries distributed by the Apache HTTP Server Project are provided as a
courtesy by individual project contributors. The project makes no
commitment to release the Apache HTTP Server in binary form for any
particular platform, nor on any particular schedule.

IMPORTANT NOTE FOR APACHE USERS: Apache 1.3 was designed for Unix OS
variants. While the ports to non-Unix platforms (such as Win32, Netware or
OS2) will function for some applications, Apache 1.3 is not designed for
these platforms. Apache 2 was designed from the ground up for security,
stability, or performance issues across all modern operating systems.
Users of any non-Unix ports are strongly cautioned to move to Apache 2.

The Apache project no longer distributes non-Unix platform binaries from
the main download pages for Apache 1.3. If absolutely necessary, a binary
may be available at http://archive.apache.org/dist/httpd/.

Apache 1.3.42 Major changes

Security vulnerabilities

The main security vulnerabilities addressed in 1.3.42 are:

*) SECURITY: CVE-2010-0010 (cve.mitre.org)
mod_proxy: Prevent chunk-size integer overflow on platforms
where sizeof(int) < sizeof(long). Reported by Adam Zabrocki.

Bugfixes addressed in 1.3.42 are:

*) Protect logresolve from mismanaged DNS records that return
blank/null hostnames.

酷毙

雷人

鲜花

鸡蛋

漂亮
  • 快毕业了,没工作经验,
    找份工作好难啊?
    赶紧去人才芯片公司磨练吧!!

最新评论

关于LUPA|人才芯片工程|人才招聘|LUPA认证|LUPA教育|LUPA开源社区 ( 浙B2-20090187 浙公网安备 33010602006705号   

返回顶部