Patch against the Apache DOS In additional response to the iDEFENSE Security Advisory 04.08.03 cited below, the Apache HTTP Server Project has published a specific patch to address this Denial of Service vulnerability for the 2.0.44 server version. The patch may or may not apply to earlier versions of Apache 2.0, and if applied to earlier versions, may or may not fully address the vulnerability. Review was limited to correcting the but in the 2.0.44 release only.
The patch can be obtained from;
http://www.apache.org/dist/httpd/patches/apply_to_2.0.44/denial_of_service_fix.patch The Apache HTTP Server project continues to caution users to obtain the latest release (2.0.45 at this time) from
http://httpd.apache.org/download.cgi