R E L A T E D   C O N T E N T
ADVERTISEMENT

Apache gives early warning for security

Open source software creator Apache Group says firms wanting early warning of security flaws must be more proactive

Roger Howorth, IT Week 15 Jul 2002
ADVERTISEMENT

Corporate IT managers have been advised that they might receive earlier notification of flaws in the Apache Web server if they join the Apache Group's developer mailing list.

The advice came from a member of the Apache Group, responding to recent criticism from Oracle that Apache had been slow to inform it of a recently-discovered flaw. Apache said that firms contributing to its developer mailing group would receive early warnings of flaws.

The news follows suggestions that some firms received late warning of a vulnerability in the Apache Web server, which Oracle uses as the core Web server in its 9i Application Server. Apache first disclosed news of the flaw on 17 June, and several other Apache distributors, including IBM and Red Hat, posted advisory notices to their users on the same day. But the news did not reach the Oracle Web site until 20 June. As a result, the systems of Oracle customers may have been vulnerable in the interim - allowing hackers to obtain remote control of unprotected servers.

This sequence of events prompted Oracle's chief security officer, Mary Anne Davidson, to launch an investigation into the way the firm works with partners such as Apache.

A source at the Apache Group said that the organisation's developer mailing list is open to the public, and most distributors of its software are active members of the group.

"All we ask is that people with an interest in this type of information join the list and demonstrate they are not simply a hacker looking for leads," he commented.

Have your say: contact IT Week

See also:

Regular changes to the Apache 2 API has developers questioning its usability  05 Sep 2002
Apache plus Red Hat gives Windows 2000 and IIS a run for their money on four-way Intel servers  21 Jun 2002

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities