Apache HTTP Server 2.4.43 released

Apache HTTP Server 2.4.43 stable version has been released , this version mainly fixes security vulnerabilities and memory leaks related errors.

  • Fix  CVE-2020-1934  security hole: mod_proxy_ftp when the agent to a malicious FTP server may use uninitialized memory. Affected version to 2.4.41 Apache HTTP Server 2.4.0
  • Fix  CVE-2020-1927  security hole: a self-referential (self-referential) and using mod_rewrite redirection configuration may be deceived by newlines encoded and redirected to a URL outside of the target rather than the requested URL . Affected version to 2.4.41 Apache HTTP Server 2.4.0
  • mod_ssl: Repair OCSP stapling response of memory leaks

Details View  https://downloads.apache.org/httpd/CHANGES_2.4.43
Download: http://httpd.apache.org/download.cgi

Apache HTTP Server (referred to as Apache) is an open-source Web server that can run on most computer operating systems, because of its multi-platform security and is widely used, is one of the most popular Web server software. It is fast, reliable, and can be extended through a simple API, the Perl / Python interpreter like compiled into the server.

Apache HTTP Server 2.4.x requires Apache Portable Runtime (APR) and the lowest minimum version 1.5.x version APR-Util 1.5.x. some features may require 1.6.x version APR and APR-Util must be upgraded to the APR library All functions of the httpd running.

This version is based on and extends the Apache 2.2 API. For the need to recompile Apache 2.2 running Apache 2.2 module is written, and require little or no source code changes.

When upgrading or installing this version, please keep in mind that if you intend to use it with one of the threads MPM (except Prefork MPM), you must ensure that any module you will be using (and the libraries they depend on) are thread-safe of.

2.2.x branch now has been the life cycle of Apache HTTP Server project, and any changes will not happen again, including security patches. Users must be completed in time for the transition of the httpd 2.4.x version, the new features in order to repair or benefit from further errors.

Guess you like

Origin www.oschina.net/news/114681/apache-http-server-2-4-43-released