CVE-2023-31122 - when will apache be patched??

Problems with the Windows version of XAMPP, questions, comments, and anything related.

CVE-2023-31122 - when will apache be patched??

Postby holly10sun » 23. October 2023 15:54

Need to know how often and how quickly XAMPP is patched to keep up with Apache patches for CVE's. Have an ACAS hit and these are not things we can let go for extended periods. If XAMPP does not keep up with Apache releases will need to find another option.

Thanks!
holly10sun
 
Posts: 3
Joined: 23. October 2023 15:48
XAMPP version: 8.2.4
Operating System: Windows

Re: CVE-2023-31122 - when will apache be patched??

Postby Altrea » 23. October 2023 18:33

Can you please describe the impact of CVE-2023-31122 on a local test and development environment?

If up to date top notch updated components and security assessments are your focus, xampp is not made for you.
We don't provide any support via personal channels like PM, email, Skype, TeamViewer!

It's like porn for programmers 8)
User avatar
Altrea
AF Moderator
 
Posts: 11934
Joined: 17. August 2009 13:05
XAMPP version: several
Operating System: Windows 11 Pro x64

Re: CVE-2023-31122 - when will apache be patched??

Postby Nobbie » 23. October 2023 23:13

holly10sun wrote: If XAMPP does not keep up with Apache releases will need to find another option


So what?
Nobbie
 
Posts: 13176
Joined: 09. March 2008 13:04

Re: CVE-2023-31122 - when will apache be patched??

Postby holly10sun » 24. October 2023 15:23

Wow! Rude! Thanks for all the help - yes security is a priority where I work. I guess we will explore better options!
holly10sun
 
Posts: 3
Joined: 23. October 2023 15:48
XAMPP version: 8.2.4
Operating System: Windows

Re: CVE-2023-31122 - when will apache be patched??

Postby Altrea » 24. October 2023 16:13

XAMPP is meant for beginners not able to install the needed single components on their own.
The disadvantage is that you are completely dependend on new releases for the whole XAMPP bundle.
You are much more free in updatability if you install the single components on your own.
We don't provide any support via personal channels like PM, email, Skype, TeamViewer!

It's like porn for programmers 8)
User avatar
Altrea
AF Moderator
 
Posts: 11934
Joined: 17. August 2009 13:05
XAMPP version: several
Operating System: Windows 11 Pro x64

Re: CVE-2023-31122 - when will apache be patched??

Postby Nobbie » 24. October 2023 22:07

holly10sun wrote:I guess we will explore better options!


And dont forget to get all your money back....
Nobbie
 
Posts: 13176
Joined: 09. March 2008 13:04

Re: CVE-2023-31122 - when will apache be patched??

Postby holly10sun » 26. October 2023 15:13

Altrea wrote:XAMPP is meant for beginners not able to install the needed single components on their own.
The disadvantage is that you are completely dependent on new releases for the whole XAMPP bundle.
You are much more free in updatability if you install the single components on your own.


Altrea, thank you for not being arrogant and rude! I am not an Apache or PHP expert. The software we are using can run on IIS or Apache. We were running it on IIS but for some reason a coworker felt it would be more stable on Apache and the vendor of the software recommends XAMPP. However we live in an IT world that is required to stay current and not have ACAS hits. The CVE is stating multiple vulnerabilities as stated in the 2.4.58 advisory. I imagine I could figure out how to get this rolling by installing the components myself but not sure how much time it will take.

I see Out of bounds read vulnerability, DoS, HTTP/2 stream memory not reclaimed all listed.

I understand this is free open source. I really just wanted to know what the "normal" time for patching is so that I can request an exception or make a different decision. We do get some leeway with exceptions but not much.
holly10sun
 
Posts: 3
Joined: 23. October 2023 15:48
XAMPP version: 8.2.4
Operating System: Windows


Return to XAMPP for Windows

Who is online

Users browsing this forum: No registered users and 189 guests