- BUGTRAQ:20020809 Apache 2.0 vulnerability affects non-Unix platforms
- BUGTRAQ:20020816 Apache 2.0.39 directory traversal and path disclosure bug
This is a serious flaw, but Apache.org was right on top of the problem. The people who discovered this vulnerability, Newport Beach, CA-based PivX Solutions, reported it to Apache.org and began working with Apache on Aug. 7, according to the PC World story. The actual upgrade was made available on Aug. 16 in conjunction with the announcement of the discovery. Apache.org acted quickly, but no one can fix such problems instantly. All it can do is work with responsible companies that uncover such threats and attempt to coordinate the announcement with the release of the patch or update. Apache.org reacted quickly and PivX Solutions acted responsibly in delaying its announcement until a new version of Apache was available. PivX also discovered another minor flaw, one that could lead to the disclosure of some relatively unimportant server owner information, but this is also fixed in the latest Apache release. One word of caution: Whenever people see that Windows systems are vulnerable to some flaw and Linux/UNIX isn't, they tend to skip over the details if they run Linux and/or UNIX. In this case, the problem has nothing directly to do with Windows code, and this vulnerability is not limited to Windows-based systems but also applies to NetWare and OS/2 platforms. It isn't a threat due to a fault in Windows code; rather, the problem lies in the fact that the backslash character isn't properly checked as a bad char in the Windows version of Apache. And while Apache.org says that it believes the UNIX versions aren't affected, you should still keep an eye on this threat for a week or two for any updates, and perhaps even consider updating Linux/UNIX systems to the latest Apache release.
Tech Update forum. Find out what's where in the new Tech Update with our
Guided Tour. Let the editors know what you think in the
Mailroom.






