Download Apache 2.0.51
The development team behind Apache has released version 2.0.51 of its HTTP server software. This release is mainly a bug fix version. The full changelog is here but these are the main bugs that have been fixed:
This version of Apache is principally a bug fix release. Of particular note is that 2.0.51 addresses five security vulnerabilities:
- An input validation issue in IPv6 literal address parsing which can result in a negative length parameter being passed to memcpy. [CAN-2004-0786]
- A buffer overflow in configuration file parsing could allow a local user to gain the privileges of a httpd child if the server can be forced to parse a carefully crafted .htaccess file. [CAN-2004-0747]
- A segfault in mod_ssl which can be triggered by a malicious remote server, if proxying to SSL servers has been configured. [CAN-2004-0751]
- A potential infinite loop in mod_ssl which could be triggered given particular timing of a connection abort. [CAN-2004-0748]
- A segfault in mod_dav_fs which can be remotely triggered by an indirect lock refresh request. [CAN-2004-0809][break]The following downloads are available:
Source code for Win32 compilers
Win32 installer
2.0.51 (tarball)
2.0.51 gzipped source
| Version number | 2.0.51 |
| Operating systems | Windows NT, Windows 2000, Linux, Windows XP, Windows Server 2003 |
| Website | Apache |
| Download | |
| License type | Conditions (GNU/BSD/etc.) |