|
发表于 2006-7-29 09:12:17
|
显示全部楼层
Fri Jul 28 17:32:54 CDT 2006
n/apache-1.3.37-i486-1.tgz: Upgraded to apache-1.3.37.
From the announcement on httpd.apache.org:
This version of Apache is security fix release only. An off-by-one flaw
exists in the Rewrite module, mod_rewrite, as shipped with Apache 1.3
since 1.3.28, 2.0 since 2.0.46, and 2.2 since 2.2.0.
The Slackware Security Team feels that the vast majority of installations
will not be configured in a vulnerable way but still suggests upgrading to
the new apache and mod_ssl packages for maximum security.
For more details, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3747
And see Apache's announcement here:
http://www.apache.org/dist/httpd/Announcement1.3.html
(* Security fix *)
n/mod_ssl-2.8.28_1.3.37-i486-1.tgz: Upgraded to mod_ssl-2.8.28-1.3.37.
+--------------------------+ |
|