Fix list for IBM HTTP Server Version 8.5

Product documentation


Abstract

IBM HTTP Server provides periodic fixes for release 8.5. The following is a complete listing of fixes for Version 8.5 with the most recent fix at the top.

Content

Back to all versions

Fix Pack 3 (8.5.5.3)
Fix Pack 2 (8.5.5.2)
Fix Pack 1 (8.5.5.1)
Refresh Pack (8.5.5)
Fix Pack 2 (8.5.0.2)
Fix Pack 1 (8.5.0.1)







Fix Pack 3 (8.5.5.3)
Fix release date: 18 August 2014
Last modified: 18 August 2014
Status: Recommended

Download Fix Pack 3

APAR Description
PI13028 CVE-2014-0098: mod_log_config - Potential denial of service vulnerability
http://www-01.ibm.com/support/docview.wss?&uid=swg21681249
PI17025 CVE-2014-0963: IBM HTTP Server high CPU utilization with SSL (includes GSKit upgrade)
http://www-01.ibm.com/support/docview.wss?&uid=swg21681249
PI19700 CVE-2014-0076: Local side-channel attack on ECDSA (GSKit upgrade)
http://www-01.ibm.com/support/docview.wss?&uid=swg21681249
PI13422 Memory leak in GSKit 8.0.50 (GSKit upgrade)
PI13949 MVSDS request does not release shared ENQ (z/OS only)
PI14451 IHS with SSLFIPSENABLE reports error code 53817451 at startup (z/OS only)
PI15344 IBM HTTP Server caching issues
PI16599 Authentication failure gives LDAP error for non-LDAP configurations
PI17434 SSLCACHE may fail due to SSLCACHEPORTFILENAME value being in use (z/OS only)


Note: IBM HTTP Server 8.5.5.3 contains all applicable security fixes in Apache HTTP Server versions up through 2.2.27.


Fix Pack 2 (8.5.5.2)
Fix release date: 28 April 2014
Last modified: 28 April 2014
Status: Superseded

Download Fix Pack 2

APAR Description
PI05309 CVE-2013-6329: SSL session resumption vulnerability. (GSKit upgrade).
http://www-01.ibm.com/support/docview.wss?&uid=swg21669554
PI09345 CVE-2013-6438: Potential Denial of Sevice in mod_dav for IBM HTTP Server.
http://www-01.ibm.com/support/docview.wss?&uid=swg21669554
PI09443 CVE-2013-6747: GSKit Certificate Chain Vulnerability. (GSKit upgrade).
http://www-01.ibm.com/support/docview.wss?&uid=swg21669554
PM94008 Timed-out ldap bind and search failures on reused connections are not retried.
PM94143 Use of SAFRunAs results in ICH408I messages to be issued against the HTTP Server userid (z/OS only)
PM94602 ProxyRemote fails to work with SSL requests
PM96039 AcceptEx disablement notice should not appear in Microsoft Windows Event Viewer
PM97650 IBM HTTP Server does not send SIGTERM to fastCGI application
PI04922 IBM HTTP Server scaling/processing threads limited on 64-bit Microsoft Windows.
PI06366 IBM HTTP Server thread creation failures when scaling up from default configuration on RHEL6
PI07665 IBM HTTP server 8.5 (Apache) on z/OS needs support of cgiparse and cgiutils from IHS 5.3 Domino Go Web Server.
PI08502 Potential heap corruption under load for IBM HTTP Server with SSL enabled. (GSKit upgrade).
PI08715 Potential mod_proxy crashes under load
PI09344 Missing version.signature file for 31-bit IBM HTTP Server on z/OS breaks 8.5.5 post-update process.


Note: IBM HTTP Server 8.5.5.2 contains all applicable security fixes in Apache HTTP Server versions up through 2.2.26.


Fix Pack 1 (8.5.5.1)
Fix release date: 11 November 2013
Last modified: 11 November 2013
Status: Superseded

Download Fix Pack 1

APAR Description
PM87808 CVE-2013-1862: mod_rewrite vulnerability
http://www-01.ibm.com/support/docview.wss?&uid=swg21651880
PM89996 CVE-2013-1896: mod_dav vulnerability
http://www-01.ibm.com/support/docview.wss?&uid=swg21651880
PM84215 mod_mpmstats may report incorrect values during startup or shutdown
PM87247 Additional certificate attributes are needed as fields accessible to the SSLClientAuthRequire directive
PM89422 IHS WebDAV requests slow on Windows
PM91704 Add mod_smf module for IBM HTTP Server (z/OS only)
PM92105 wlm enclave support fails on a child process without a unique jobname (z/OS only)


Note: IBM HTTP Server 8.5.5.1 contains all applicable security fixes in Apache HTTP Server versions up through 2.2.25.


Refresh Pack (8.5.5)
Fix release date: 14 June 2013
Last modified: 14 June 2013
Status: Superseded

Download Refresh Pack 8.5.5

APAR Description
PM85211 CVE-2013-0169: TLS Vulnerability (The fix upgrades the bundled GSKit security library)
http://xforce.iss.net/xforce/xfdb/81902


Note: IBM HTTP Server 8.5.5 contains all applicable security fixes in Apache HTTP Server versions up through 2.2.24.


Fix Pack 2 (8.5.0.2)
Fix release date: 15 April 2013
Last modified: 15 April 2013
Status: Superseded

Download Fix Pack 2

APAR Description
PM76110 CVE-2012-4557: mod_proxy_ajp incorrectly marks backend WAS CE server down
PM80058 CVE-2012-3499/CVE-2012-4558: Potential exposure in several IBM HTTP Server optional modules
http://xforce.iss.net/xforce/xfdb/82359
http://xforce.iss.net/xforce/xfdb/82360
PM68347 Z/OS IHS config for versions prior to 8.5 may not migrate as expected to 8.5
PM69188 Installation of IBM HTTP Server V8.5 completes with a warning. Failure occurs because the system's hostname is not set.
PM70591 IHS on Microsoft Windows startup failure with SSLv3Timeout or SSLv2Timeout in vhost: 'master_main: create child process failed.'
PM70994 SSLFakeBasicAuth depends on LoadModule order
PM71102 <Location> settings don't affect some mod_negotiation generated content
PM73304 Add mod_ssl's SSLProxyCheckPeerCN to IBM HTTP Server
PM75876 The 'Header' directive can't set a header only if the header is absent, even when using 'EDIT' mode or relying on other modules.
PM77980 IBM HTTP Server should not add the Server: header by default
PM78087 IBM HTTP Server high memory use when many hundreds of RewriteCond %{REQUEST_URI}
PM78144 IBM HTTP Server large logformats cannot be correctly logged by piped loggers
PM78434 Provide end-to-end timeouts for SSL handshakes
PM79015 mod_disk_cache on Windows gives error: '(OS 5) Access is denied: disk_cache: Rename tempfile to datafile failed'
PM80235 NIST SP800-131a support for IBM HTTP Server
PM80260 apr_pollset_add failure -errno2=0X11780494, or growing CPU usage on the listener thread in IHS child processes (z/OS only)


Note: IBM HTTP Server 8.5.0.2 contains all applicable security fixes in Apache HTTP Server versions up through 2.2.24.


Fix Pack 1 (8.5.0.1)
Fix release date: 29 October 2012
Last modified: 29 October 2012
Status: Superseded

Download Fix Pack 1

APAR Description
PM66218 Upgrade bundled GSKit security library
http://www-01.ibm.com/support/docview.wss?&uid=swg21614265
PM66470 CVE-2012-2687: mod_negotiation - potential information disclosure on compromised site.
PM72915 TLS compression should be disabled by default in IBM HTTP Server
http://www-01.ibm.com/support/docview.wss?uid=swg21611881
PM62011 mod_log_config: The wrong cookie can be logged
PM63634 admin.passwd file was reset after installing fixpack
PM68007 Non-root IBM HTTP Server install fails if primary group has no name
PM71612 Additional non-serviceable files added for IBM HTTP Server


Note: IBM HTTP Server 8.5.0.1 contains all applicable security fixes in Apache HTTP Server versions up through 2.2.23.

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

IBM HTTP Server

Software version:

8.5, 8.5.0.1, 8.5.0.2, 8.5.5, 8.5.5.1, 8.5.5.2, 8.5.5.3

Operating system(s):

AIX, HP-UX, Linux, Solaris, Windows, z/OS

Reference #:

7036410

Modified date:

2014-08-18

Translate my page

Machine Translation

Content navigation