Update (04/04/2005): This page is *very* out of date! Do not use these packages!

Fixed apache-1.3.24 (Apache Web Server Chunk Handling Vulnerability)
Used patches: sec1.patch & sec2.patch taken from the Apache CVS.

These packages have been localy tested but are unsupported.

-rw-r--r--    1 root     root       811690 Jun 18 12:37 apache-common_1.3.24-3.secfix2_i386.deb
-rw-r--r--    1 root     root       540752 Jun 18 12:37 apache-dev_1.3.24-3.secfix2_i386.deb
-rw-r--r--    1 root     root       970118 Jun 18 12:37 apache-doc_1.3.24-3.secfix2_all.deb
-rw-r--r--    1 root     root       362102 Jun 18 12:37 apache_1.3.24-3.secfix2.diff.gz
-rw-r--r--    1 root     root          778 Jun 18 12:37 apache_1.3.24-3.secfix2.dsc
-rw-r--r--    1 root     root         1518 Jun 18 12:37 apache_1.3.24-3.secfix2_i386.changes
-rw-r--r--    1 root     root       355116 Jun 18 12:37 apache_1.3.24-3.secfix2_i386.deb
-rw-r--r--    1 root     root         1400 Jun 18 12:39 sec1.patch
-rw-r--r--    1 root     root          498 Jun 18 12:39 sec2.patch

Update: Official Debian packages are now out

-rw-r--r--    1 root  root    813220 Jun 20 12:45 apache-common_1.3.26-1_i386.deb
-rw-r--r--    1 root  root    535022 Jun 20 12:45 apache-dev_1.3.26-1_i386.deb
-rw-r--r--    1 root  root    293252 Jun 20 12:45 apache_1.3.26-1.diff.gz
-rw-r--r--    1 root  root       707 Jun 20 12:45 apache_1.3.26-1.dsc
-rw-r--r--    1 root  root    352752 Jun 20 12:45 apache_1.3.26-1_i386.deb
-rw-r--r--    1 root  root   2586182 Jun 20 12:46 apache_1.3.26.orig.tar.gz

Vincent Renardias
vincent@debian.org

(C) 2002