According to cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3192]CVE - CVE-2011-3192 (under review, which is sponsored by the US State dept. of Homeland Security, and Apache's own website: mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD@minotaur.apache.org%3e , there is a newly discovered DoS exploit in versions of Apache prio to v2.2.19 inclusive.
I wonder whether reports seen on this forums that some VSP accounts were experiencing 'unexplained' memory/cpu overload was caused by this exploit?
A new version 2.2.2 has been released by Apache that would fix this vulnerability. But I am not sure it is whose responsibility to upgrade Apache? is it eUK technical team, or the account holders? or is it that eUK thinks this exploit does not affect eUK servers?
edit: I am told I cant post URLs so I have to delete the http bit. you will have to copy and paste if you are interested.


Reply With Quote