Originally posted by: JoachimB
The httpd package on the Web Download Pack site is version 2.4.4.
I got the information that any version earlier than 2.4.5. is affected by the following vulnerabilities :
- A denial of service vulnerability exists relating to the 'mod_dav' module as it relates to MERGE requests.
(CVE-2013-1896)
- An error exists related to the 'mod_session_dbd' module, flags and session-saving having an unspecified impact.
(CVE-2013-2249)
When will the httpd package be updated?