Apache squashes 'Apache killer' bug
Maintainers of the open-source Apache webserver have fixed a severe weakness that attackers are exploiting to crash websites.
Flaws in Apache's HTTP daemon made it easy to crash servers using publicly available software released last week. The bugs in the way the HTTPD processed multiple web requests that involved overlapping byte ranges allowed attackers to overwhelm servers by sending them a modest amount of traffic.
An advisory on Apache's website said the bug, formally known as CVE-2011-3192 has been fixed in version 2.2.20. “We consider this release to be the best version of Apache available, and encourage users of all prior versions to upgrade,” the advisory stated. "Active use" of the attack tool has been observed.