Apache HTTP Server 1.3.31 Released

1.3.30 は欠番になったんですね。脆弱性が4つほど修正されてます。[ChangeLog for 1.3.31]

  • CAN-2003-0987: In mod_digest, verify whether the nonce returned in the client response is one we issued ourselves. This problem does not affect mod_auth_digest.
  • CAN-2003-0020: Escape arbitrary data before writing into the errorlog.
  • CAN-2004-0174: Fix starvation issue on listening sockets where a short-lived connection on a rarely-accessed listening socket will cause a child to hold the accept mutex and block out new connections until another connection arrives on that rarely-accessed listening socket.
  • CAN-2003-0993: Fix parsing of Allow/Deny rules using IP addresses without a netmask; issue is only known to affect big-endian 64-bit platforms