On 24th of August a new vulnerability in 1.3 and 2.x Apache servers was published. Vulnerablility (referenced as CVE-2011-3192) results in DoS attack by significant CPU and memory usage. Flaw can be exploited by by crafting HTTP requests with overlapping "range" headers. All needed patches should be released soon (in a matter of hours). So far there is possibility to secure server by changing its configuration. More information can be found here:
pl
en
