Security patches for Apache 1.3.x?

Security patches for Apache 1.3.x?

Ira Abramov Lists-Linux-IL at ira.abramov.org
Thu Jul 14 16:29:00 IDT 2011


howdie!

I have an embeded system (roughly based on CentOS 3) with a few legacy
components, one of which is Apache 1.3.42, which has served us well this
far, but now we bumped into these:

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1928
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-0419

Since the Apache 1.x line is EOL and I don't see this package has been
maintained with sec patches by Debian or even RHEL (correct me if I
missed anything)

Before I'm forced to rock the boat with a move to Apache2, lighty or
nginx, is there a source for patches for this that I missed?

Thanks,
Ira.

-- 
Patron of the arts
Ira Abramov
http://ira.abramov.org/email/



More information about the Linux-il mailing list