[Announcement] Apache HTTP Server 2.4.28 Released

2017-10-05 Thread William A Rowe Jr
Apache HTTP Server 2.4.28 Released October 5, 2017 The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.4.28 of the Apache HTTP Server ("Apache"). This version of Apache is our latest GA release of the new generation 2.4.

CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest

2017-07-13 Thread William A Rowe Jr
CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest Severity: Important Vendor: The Apache Software Foundation Versions Affected: all versions through 2.2.33 and 2.4.26 Description: The value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or rese

CVE-2017-9789: Apache httpd 2.4 Read after free in mod_http2

2017-07-13 Thread William A Rowe Jr
CVE-2017-9789: Read after free in mod_http2.c Severity: Important Vendor: The Apache Software Foundation Versions Affected: httpd 2.4.26 Description: When under stress, closing many connections, the HTTP/2 handling code would sometimes access memory after it has been freed, resulting in potenti

[Announcement] Apache HTTP Server 2.2.34 Released

2017-07-11 Thread William A Rowe Jr
July 11, 2017 The Apache Software Foundation and the Apache HTTP Server Project announce the release of version 2.2.34 of the Apache HTTP Server ("Apache"), the final maintenance release of the 2.2 series. No further 2.2 releases are anticipated. This version of Apache is princip

[Announce] Apache HTTP Server 2.2.29 Released

2014-09-03 Thread William A. Rowe Jr.
Apache HTTP Server 2.2.29 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.29 of the Apache HTTP Server ("Apache"). (Note that 2.2.28 was not released). This version of Apache is princip

[Announcment] Apache HTTP Server 2.2.27 Released

2014-03-26 Thread William A. Rowe Jr.
Apache HTTP Server 2.2.27 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.27 of the Apache HTTP Server ("Apache"). This version of Apache is principally a security and bug fix maintena

Apache HTTP Server 2.2.24 Released

2013-02-26 Thread William A . Rowe Jr .
The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.24 of the Apache HTTP Server ("Apache"). This version of Apache is principally a security and bug fix maintenance release, including the following significant securit

Apache HTTP Server 2.2.22 Released

2012-01-31 Thread William A. Rowe Jr.
Apache HTTP Server 2.2.22 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.22 of the Apache HTTP Server ("Apache"). This version of Apache is principally a security and bug fix release,

Apache HTTP Server 2.2.21 Released

2011-09-13 Thread William A. Rowe Jr.
The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.21 of the Apache HTTP Server ("Apache"). This version of Apache is principally a security and bug fix release: * SECURITY: CVE-2011-3348 (cve.mitre.org) mod

Apache HTTP Server 2.2.19 Released

2011-05-22 Thread William A. Rowe Jr.
Apache HTTP Server 2.2.19 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.19 of the Apache HTTP Server ("Apache"). This version of Apache is principally a bug fix release, correcting r

[Announce] Regressions in httpd 2.2.18, apr 1.4.4, and apr-util 1.3.11

2011-05-19 Thread William A. Rowe Jr.
New releases are in progress for each of these projects and are expected to be available in the coming days. The upcoming httpd 2.2.19 will bundle new releases of apr and apr-util which correct the regressions described below. An announcement of these releases will be broadcast. Note: httpd 2.2

[Announce] Apache HTTP Server 2.2.18 Released

2011-05-11 Thread William A. Rowe Jr.
Apache HTTP Server 2.2.18 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.18 of the Apache HTTP Server ("Apache"). This version of Apache is principally a bug fix release, and a securi

[announce] Apache HTTP Server 2.2.17 and 2.0.64 Released

2010-10-19 Thread William A. Rowe Jr.
The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.17 of the Apache HTTP Server ("Apache"). This version of Apache is principally a bug fix release, and a security fix release of the APR-util 1.3.10 dependency; *

[advisory] httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068

2010-06-11 Thread William A. Rowe Jr.
Vulnerability; httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068 Classification; important Description; A timeout detection flaw in the httpd mod_proxy_http module causes proxied response to be sent as the response to a different request, and potentially served to a differe

[Announce] Apache HTTP Server (httpd) 2.2.15 Released

2010-03-06 Thread William A. Rowe Jr.
The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release and immediate availability of version 2.2.15 of the Apache HTTP Server ("httpd"). This version of httpd is principally a security and bug fix release. Notably, this release was updated to reflect

Apache Portable Runtime 1.2.12 Released

2007-11-26 Thread William A. Rowe, Jr.
Apache Portable Runtime 1.2.12 Released The Apache Software Foundation and the Apache Portable Runtime Project are proud to announce the General Availability of version 1.2.12 of the APR Apache Portable Runtime library. The Project further announces the General Availability of APR-ut

[Announce] Apache HTTP Server 2.2.4 Released

2007-01-10 Thread William A. Rowe, Jr.
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Apache HTTP Server 2.2.4 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.4 of the Apache HTTP Server ("Apache"). This version of Apache is principally a

[Announce] New (relocated) modules-dev@httpd.apache.org list

2006-09-08 Thread William A. Rowe, Jr.
Following a vote on dev@httpd.apache.org, and with input from the project participants on the [EMAIL PROTECTED] Authors' discussion list, the httpd project is pleased to announce the creation of a new modules-dev list at httpd.apache.org. Current subscribers to the apache-modules list will not be

[Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released

2006-07-28 Thread William A. Rowe, Jr.
Apache HTTP Server 2.2.3 Released The Apache Software Foundation and The Apache HTTP Server Project are pleased to announce the release of version 2.2.3 of the Apache HTTP Server ("Apache"). This version of Apache is principally a bug and security fix release. The following p

[Announce] Apache HTTP Server 2.0.55 Released

2005-10-14 Thread William A. Rowe, Jr.
Apache HTTP Server 2.0.55 Released The Apache Software Foundation and The Apache HTTP Server Project are pleased to announce the release of version 2.0.55 of the Apache HTTP Server ("Apache"). This Announcement notes the significant changes in 2.0.55 as compared to 2.0.

[ANNOUNCE] Apache 2.0.45 Released

2003-04-02 Thread William A. Rowe, Jr.
Apache 2.0.45 Released The Apache Software Foundation and The Apache HTTP Server Project are pleased to announce the eighth public release of the Apache 2.0 HTTP Server. This Announcement notes the significant changes in 2.0.45 as compared to 2.0.44. OS2 users; note that Apa

[Security Release] Apache HTTP Server 2.0.43

2002-10-03 Thread William A. Rowe, Jr.
-BEGIN PGP SIGNED MESSAGE- Apache 1.3.27 Released The Apache Software Foundation and The Apache Server Project are pleased to announce the release of version 1.3.27 of the Apache HTTP Server. This Announcement notes the significant changes in 1.3.27