Apache version older than 1.3.37
Apache version older than 1.3.37
Published on 2008-06-12. Updated on 2008-06-12.
Description:
This alert was generated using only banner information. It may be a false positive.
Security fixes in Apache version 1.3.37:
- CVE-2006-3747 (cve.mitre.org) mod_rewrite: Fix an off-by-one security problem in the ldap scheme handling. For some RewriteRules this could lead to a pointer being written out of bounds. Reported by Mark Dowd of McAfee. [Mark Cox]
Affected Apache versions (up to 1.3.36).
Impact:
Check references for details about each vulnerability.
Recommendation:
Upgrade Apache to the latest version.
Alert Tags: configuration
ApplicableApplicationServer : All
ApplicableOS: All
ApplicableWebServer: Apache
References:
Go Back