Do You PHP はてブロ

Do You PHPはてなからはてブロに移動しました

Apache2.0.57がリリースされる模様

バグFIX&セキュリティFIX版のようです。

This version of Apache is principally a bug and security fix release.
The following potential security flaws are addressed;

CVE-2005-3357 (cve.mitre.org)

mod_ssl: When configured with an SSL vhost with access control and a
custom error 400 error page, mod_ssl allows remote attackers to cause
a denial of service (application crash) via a non-SSL request to an
SSL port, which triggers a NULL pointer dereference.

CVE-2005-3352 (cve.mitre.org)

mod_imap: Cross-site scripting (XSS) vulnerability which allows remote
attackers to inject arbitrary web script or HTML via the Referer when
using image maps.

CHANGES_2_0をみると、2.0.56(未リリース)で広範囲に渡り色々直されているようです。