Study: Admins slow in patching Apache-SSL servers

InfoWorld | at | by Mike

Many web servers running Apache-SSL remain vulnerable to attacks, although a June security alert did prompt administrators to patch standard Apache Web installations, according to a survey released Tuesday. About 75 percent of Web sites hosted on Apache-SSL servers are vulnerable, as the software has not been upgraded to fix a serious flaw uncovered in June, according to a survey by Web server information firm Netcraft Ltd. of Bath, England.

Administrators seem to have given priority to patching regular Apache installations, as about half of the 22 million Web sites that rely on Apache are protected through an Apache software upgrade, Netcraft said. The flaw affects all versions of Apache 1.2, versions of Apache 1.3 up to 1.3.24 and versions of Apache 2 up to 2.0.36, according to a statement from the Foundation released on June 20.