Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 8 Apr 2004 12:27:23 +0100
From:      Matthew Seaman <m.seaman@infracaninophile.co.uk>
To:        Mark <admin@asarian-host.net>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Fw: Rewriting long URIs from viruses... shortening log files
Message-ID:  <20040408112723.GE71019@happy-idiot-talk.infracaninophile.co.uk>
In-Reply-To: <200404081050.I38AOWNT082514@asarian-host.net>
References:  <200404081050.I38AOWNT082514@asarian-host.net>

next in thread | previous in thread | raw e-mail | index | archive | help

--10jrOL3x2xqLmOsH
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Apr 08, 2004 at 10:50:33AM +0000, Mark wrote:
> Purl Gurl (in alt.apache.configuration) wrote:
>=20
> > tz wrote:

> >> Running Apache/1.3.27 (Unix) here.
> >
> > Excellent. Apache 1.3.27 is the best
> > version of all Apache releases. Next
> > two, .28 and .29 have some bugs.
>=20
> Is this true? I very much doubt it. Since I recently upgraded to 1.3.29
> myself (on FreeBSD 4.9R-p3), it doesn't hurt to ask, though.

It's not in agreement with what it says on http://httpd.apache.org/.
apache-1.3.29 is a security release, as well as being a bug fix
release.

The Apache Software Foundation is not shy about admitting mistakes or
shortcomings: if they felt that an older release was substantially
better for most people to run, that information would be plastered all
over their front page.

There is a bug to do with mod_usertrack and the CookieName directive
which is a current issue in the latest versions of apache.  However,
it's something that will only affect a few apache users, and there's a
simple work-around.  It's not so significant they've produced a new
release right away, nor is it anything like as important as the buffer
overflow fixed with the release of 1.3.29, exploitation of which could
allow an attacker to DoS your server or even run arbitrary code upon
it.

	Cheers,

	Matthew

--=20
Dr Matthew J Seaman MA, D.Phil.                       26 The Paddocks
                                                      Savill Way
PGP: http://www.infracaninophile.co.uk/pgpkey         Marlow
Tel: +44 1628 476614                                  Bucks., SL7 1TH UK

--10jrOL3x2xqLmOsH
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFAdTcbdtESqEQa7a0RAj7RAJwOTst4VSsY2dTvy6OYBrn22xbpDQCfR8E4
h1gQWFSFoWEqleJANsKt2w4=
=UyiI
-----END PGP SIGNATURE-----

--10jrOL3x2xqLmOsH--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040408112723.GE71019>