Community Forums
Connect with us on LinkedIn
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Feb 2007
    Posts
    286

    Default Apache HTTP Server 2.2.22 Released [Case 56985]

    * SECURITY: CVE-2011-3368 (cve.mitre.org)
    Reject requests where the request-URI does not match the HTTP
    specification, preventing unexpected expansion of target URLs in
    some reverse proxy configurations.

    * SECURITY: CVE-2011-3607 (cve.mitre.org)
    Fix integer overflow in ap_pregsub() which, when the mod_setenvif module
    is enabled, could allow local users to gain privileges via a .htaccess
    file.

    * SECURITY: CVE-2011-4317 (cve.mitre.org)
    Resolve additional cases of URL rewriting with ProxyPassMatch or
    RewriteRule, where particular request-URIs could result in undesired
    backend network exposure in some configurations.

    * SECURITY: CVE-2012-0021 (cve.mitre.org)
    mod_log_config: Fix segfault (crash) when the '%{cookiename}C' log format
    string is in use and a client sends a nameless, valueless cookie, causing
    a denial of service. The issue existed since version 2.2.17.

    * SECURITY: CVE-2012-0031 (cve.mitre.org)
    Fix scoreboard issue which could allow an unprivileged child process
    could cause the parent to crash at shutdown rather than terminate
    cleanly.

    * SECURITY: CVE-2012-0053 (cve.mitre.org)
    Fixed an issue in error responses that could expose "httpOnly" cookies
    when no custom ErrorDocument is specified for status code 400.
    Apache HTTP Server 2.2.22 Released | Apache | Dev

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Apache HTTP Server 2.2.22 Released [Case 56985]

    Given the security implications, this already has been assigned the highest level of priority so we should be seeing this in EasyApache in the coming days.

  3. #3
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,782
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Apache HTTP Server 2.2.22 Released [Case 56985]

    This will be part of EasyApache 3.9, which is the next release.
    Kenneth
    Product Manager
    cPanel, Inc.

  4. #4
    Member
    Join Date
    Jan 2008
    Posts
    39
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Apache HTTP Server 2.2.22 Released [Case 56985]

    Any word on when this might be coming? I notice that PHP 5.3.10 was added to EA today, but still no sign of Apache 2.2.22.

  5. #5
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Apache HTTP Server 2.2.22 Released [Case 56985]

    Quote Originally Posted by LDHosting View Post
    Any word on when this might be coming? I notice that PHP 5.3.10 was added to EA today, but still no sign of Apache 2.2.22.
    Working on it... thinking a scale of days rather than hours though.

  6. #6
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Apache HTTP Server 2.2.22 Released [Case 56985]

    Apache 2.2.22 is now available in EasyApache 3.9.1 which is on all update tiers at the moment. I am closing and archiving this thread.

Similar Threads & Tags
Similar threads

  1. Filed with Developers Apache HTTP Server 2.2.21 Released [Cases 53139, 53140]
    By Ivan A in forum Feature Requests for cPanel/WHM
    Replies: 3
    Last Post: 09-15-2011, 09:14 AM
  2. [Case 52785] Apache HTTP Server 2.2.20 Released
    By Ivan A in forum Archived Feature Requests
    Replies: 6
    Last Post: 09-06-2011, 07:41 AM
  3. Apache HTTP Server 2.2.19 Released [Case 50042, Case 50053]
    By sparek-3 in forum Archived Feature Requests
    Replies: 8
    Last Post: 05-26-2011, 02:20 PM
  4. Apache HTTP Server 1.3.34 Released
    By SupermanInNY in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 10-21-2005, 08:31 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube