Windows Apache security bug revealed
Serious hole, easy fix
Posted in Software, 15th August 2002 02:11 GMT
See what The Register's experts have to say on application security
Default installations of Apache on Windows are susceptible to a bug discovered by Italian researcher Luigi Auriemma, Apache.org reports.
According to a PivX advisory, non-Unix platforms like Windows OS2 and Netware are vulnerable, but Unix versions are not.
Details are sketchy to discourage immediate exploitation, but the organization says it will post additional details 'in the coming weeks'.
Meanwhile, the fix is simple. Add the following line to the httpd.conf file before the first 'Alias' or 'Redirect' directive:
RedirectMatch 400 "\\\.\."
The fix is included in version 2.0.40, along with fixes for "two minor path-revealing exposures," Apache says. Apache fixed the binaries within 24 hours of initial notification, PivX notes. ®
See what The Register's experts have to say on application security


Airport insecurity: the case of lost laptops
The business case for application security
Exchange 2007 risks and mitigation strategies
The best practices guide for application security
Google code cloud punts on-demand embarrassment
Microsoft weighs next-phase in open-source support
iTunes minus the player: hack your Apple beats
Oracle plans cloud strategy