[MS4W-Users] Apache in MS4W?

Jeff McKenna jmckenna at gatewaygeomatics.com
Fri Oct 15 21:32:42 UTC 2021


I'm in the process of upgrading all libraries, and especially Apache 
(see the Apache ticket at https://ms4w.com/trac/ticket/339 ), for the 
next MS4W release.  Thanks for mentioning this, as it is very important. 
  To be honest a lot of efforts have been put into the upcoming 
MapServer 8 release, and the next MS4W release will be timed for that.

But in the future, if you do see something that needs upgrading please 
do file a ticket there in the issue tracker right away, as it really 
helps to get things moving, tracking the changes, and giving you 
automated notices of any changes made.

Alternatively you can always contact me directly if your organization 
needs something sooner than the next MS4W release, at any time.

Thanks for the nudge on this, appreciated.

Have a nice weekend,


-jeff


--

Thank-you for using MS4W.
"MS4W: open doors as well as windows"






-- 
Jeff McKenna
GatewayGeo: Developers of MS4W, MapServer Consulting and Training
co-founder of FOSS4G
http://gatewaygeo.com/




On 2021-10-15 6:03 p.m., Andrew Tegenkamp via MS4W-Users wrote:
> We are using MS4W 4.0.5 and so our Apache version is 2.4.46, and were 
> recently asked about the "Path Traversal and Remote Code Execution 
> vulnerabilities (CVE-2021-41773, CVE-2021-42013) in Apache HTTP Server" 
> as that patch is making the rounds on security and tech sites.
> 
> My current best understanding is a quote from a ZDNet article that says 
> "This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier 
> versions." but I'd like to be sure and confirm this.  That said, I want 
> to provide the correct information to the person asking, and am reaching 
> out to see if the Apache in MS4W needs a patch, upgrade, or no action.
> 
> Can anyone that knows please help me understand this specifically and 
> any tips or best practices used to deal with Apache news like this in 
> the future?
> 
> Thanks.
> 
> RE: 
> https://www.zdnet.com/article/additional-fixes-released-addressing-apache-http-server-issue/ 
> <https://www.zdnet.com/article/additional-fixes-released-addressing-apache-http-server-issue/> 
> 
> 


More information about the MS4W-Users mailing list