Apache version older than 1.3.39

Apache version older than 1.3.39

Published on 2008-06-12. Updated on 2008-06-12.

Description:

This alert was generated using only banner information. It may be a false positive.

Security fixes in Apache version 1.3.39:
  • CVE-2006-5752 (cve.mitre.org) mod_status: Fix a possible XSS attack against a site with a public server-status page and ExtendedStatus enabled, for browsers which perform charset "detection". Reported by Stefan Esser. [Joe Orton]
  • CVE-2007-3304 (cve.mitre.org) Ensure that the parent process cannot be forced to kill non-child processes by checking scoreboard PID data with parent process privately stored PID data. [Jim Jagielski]

Affected Apache versions (up to 1.3.38).

Impact:
Check references for details about each vulnerability.

Recommendation:
Upgrade Apache to the latest version.

Tags: Scripts

Alert Tags: configuration
ApplicableApplicationServer : All
ApplicableOS: All
ApplicableWebServer: Apache

References:

  • Apache HTTP Server 1.x announcement
  • Apache homepage

  • Go Back