This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Apache HTTP Server 1.3.34 Released

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.apache.org/dist/httpd/Announcement1.3.html
2005-10-19
"This version of Apache is principally a bug and security fix release. A partial summary of the bug fixes is given at the end of this document. A full listing of changes can be found in the CHANGES file. Of particular note is that 1.3.34 addresses and fixes 2 potential security issues:
* If a request contains both Transfer-Encoding and Content-Length headers, remove the Content-Length, mitigating some HTTP Request Splitting/Spoofing attacks.
* Added TraceEnable [on|off|extended] per-server directive to alter the behavior of the TRACE method.
We consider Apache 1.3.34 to be the best version of Apache 1.3 available and we strongly recommend that users of older versions, especially of the 1.1.x and 1.2.x family, upgrade as soon as possible. No further releases will be made in the 1.2.x family.

Apache 1.3.34 is available for download from
http://httpd.apache.org/download.cgi

Security vulnerabilities
The main security vulnerabilities addressed in 1.3.34 are:
* If a request contains both Transfer-Encoding and Content-Length headers, remove the Content-Length, mitigating some HTTP Request Splitting/Spoofing attacks.
* Added TraceEnable [on|off|extended] per-server directive to alter the behavior of the TRACE method…"

:huh:
FYI…(correction - multiple versions updated)

- http://www.internetnews.com/security/article.php/3557521
October 19, 2005
"…Apache HTTP Server 1.3.34 and Apache HTTP Server 2.0.55 are both principally security and bug fix releases.

The Apache 1.3.34 release addresses two potential security issues. A TraceEnable per server directive has been added and a change made to the code to remove Content-Length headers when a request includes both Transfer-Encoding and Content-Length headers which could potentially lead to a HTTP Request Splitting/Spoofing attack.
- http://www.apache.org/dist/httpd/Announcement1.3.html

Apache 2.0.55 addresses six security issues, three of which are related to HTTP Request and Response Splitting/Spoofing attacks…"
- http://www.apache.org/dist/httpd/Announcement2.0.html

:huh: