首页 | 项目 | 资讯 | 专题 | 文档 | 服务 | 留言
简介 | 资讯 | 教程 | 版本 | 工具 | 手册 | 服务 | 讨论

Apache 2.0.58 Released

2006-05-08 [URL:http://apache.p.cosrc.com/see.s/ver/13]

主要修正的问题:

CVE-2005-3357 (cve.mitre.org)

mod_ssl: When configured with an SSL vhost with access control and a custom error 400 error page, mod_ssl allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.

CVE-2005-3352 (cve.mitre.org)

mod_imap: Cross-site scripting (XSS) vulnerability which allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.