Apache HTTP Server v2.2.20 released…
- http://h-online.com/-1333766
31 August 2011 - "… Apache HTTP Server 1.3.x and 2.x.x to 2.2.19 are affected; updating to 2.2.20 fixes the flaw. As active use of the Apache Killer tool has been observed, the developers encourage all users to upgrade to the latest version…"
Apache v2.2.21 released
- http://h-online.com/-1343066
14 September 2011 - "The Apache Foundation has announced* that the newly released version 2.2.21 of its free web server is essentially a bug fix and security release… The new version corrects and complements the first fix, which was released only two weeks ago… Users are advised to update their Apache installations as soon as possible. However, those who use Apache 2.0 will still need to wait: corrections for this version are scheduled to be incorporated in the release of version 2.0.65 in the near future. Those who use version 1.3 are not affected by the byte range bug…"
Oracle security alert for CVE-2011-3192
- https://isc.sans.edu/diary.html?storyid=11602
Last Updated: 2011-09-18 00:22:30 UTC - "… from the description:
'This security alert addresses the security issue CVE-2011-3192*, a denial of service vulnerability in Apache HTTPD, which is applicable to Oracle HTTP Server products** based on Apache 2.0 or 2.2. This vulnerability may be remotely exploitable without authentication, i.e. it may be exploited over a network without the need for a username and password. A remote user can exploit this vulnerability to impact the availability of un-patched systems'…"
* http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2011-3192
Last revised: 09/23/2011
CVSS v2 Base Score: 7.8 (HIGH)