This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Phil Muncaster
31 Aug 2011
IT administrators running Apache web servers have been urged to update to version 2.2.20 of the Apache HTTPD server to protect against a denial-of-service (DoS) vulnerability being exploited in the wild.
The Apache Software Foundation (ASF) warned last week of an attack tool in the wild designed to take advantage of the flaw, which affects all versions of Apache 1.3 and Apache 2.
"A DoS vulnerability has been found in the way the multiple overlapping ranges are handled by the Apache HTTPD server," the advisory said at the time.
"An attack tool is circulating in the wild. Active use of this has been observed. The attack can be done remotely and, with a modest number of requests, can cause very significant memory and CPU use on the server."
The ASF has now released an update to the web server software which will "fix handling of byte-range requests to use less memory, to avoid denial of service".
Chester Wisniewski, senior security advisor at Sophos Canada, said that all IT admins should apply the fix as soon as possible.
"Unfortunately, as we see all too frequently, many Linux and Unix administrators 'set and forget' their installations and never bother to look after their servers," he added.
"The Apache team should be applauded for testing and releasing an important security fix so quickly. Now it is up to you, the IT administrators who are using Apache, to follow through and apply these fixes."
Apache web servers are the most popular on the planet, various estimates putting its share of the market at around 65 per cent.
Latest stories from Security
Related articles
Related jobs
Poll
Which productivity tools do you use for work?
V3 pits Sony's rugged flagship against Apple's premier handset
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
Oracle DBA - Development Location: Caerphilly, South...
A fantastic opportunity for a graduate with experience...
Lead Java Developer, EMEA, Credit Bond Trading, Core...
Position-Citrix Consultant- Citrix - XenServer - XenDesktop...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree