Remix.run Logo
teddyh 2 days ago

> It seems like the bug was originally introduced here: […]

So, two weeks ago? Meaning, everybody running a version of Apache older than two weeks is safe?

st_goliath 2 days ago | parent [-]

Sure looks like it, the commit that introduced this is from July 7th, the affected version (Apache 2.4.64) was released on July 10th. Today (as of writing this in CEST) is the 24th.

It looks like not even Arch Linux had that version in their repo yet (currently 2.4.63-3) [1]

[1] https://archlinux.org/packages/extra/x86_64/apache/

captn3m0 2 days ago | parent [-]

https://repology.org/project/apache/versions

Main ones: FreeBSD, Alpine, Fedora 42, OpenSUSE Tumbleweed