{"id":115053,"date":"2024-04-14T14:30:16","date_gmt":"2024-04-14T12:30:16","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-http-serverov-lighttpd-1-4-76-i-apache-httpd-2-4-59"},"modified":"2024-04-14T14:30:16","modified_gmt":"2024-04-14T12:30:16","slug":"reliz-http-serverov-lighttpd-1-4-76-i-apache-httpd-2-4-59","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/reliz-http-serverov-lighttpd-1-4-76-i-apache-httpd-2-4-59","title":{"rendered":"Ver\u00f6ffentlichung der HTTP-Server Lighttpd 1.4.76 und Apache httpd 2.4.59","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Die Ver\u00f6ffentlichung der leichtgewichtigen HTTP-Server-Software lighttpd 1.4.76 wurde herausgegeben, die auf eine Kombination aus hoher Leistung, Sicherheit, Standardkonformit\u00e4t und Anpassungsf\u00e4higkeit abzielt. Lighttpd ist f\u00fcr den Einsatz in stark ausgelasteten Systemen geeignet und optimiert f\u00fcr geringen Speicher- und CPU-Verbrauch. Der Projektcode ist in C geschrieben und wird unter der BSD-Lizenz vertrieben.  <\/p>\n<p>In der neuen Version:  <\/p>\n<ul>\n<li class=\"l\"> Die Erkennung eines Angriffs \u201eContinuation flood\u201c wurde sichergestellt, der durch das Senden von <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/server\/\"   title=\"Server\" data-wpil-keyword-link=\"linked\">Server<\/a> HTTP\/2 ununterbrochenen CONTINUATION-Frame-Stroms ohne Setzen des END_HEADERS-Flags durchgef\u00fchrt werden. Es wird behauptet, dass dieser Angriff nicht zu einem Denial-of-Service (DoS) von lighttpd f\u00fchrt, aber als zus\u00e4tzliche Ma\u00dfnahme wurde die Erkennung hinzugef\u00fcgt, die eine GO_AWAY-Antwort sendet.\n<li class=\"l\"> Ein Vorfall der Hinterlegung eines Backdoors im xz-Paket wurde ber\u00fccksichtigt. Bei der Erstellung von Releases zum Zusammenstellen von Abh\u00e4ngigkeiten wird jetzt der Code mit dem Befehl \u201egit archive\u201c aus Git abgerufen, mit einer \u00dcberpr\u00fcfung anhand der Release-Tags und ohne die Fertigarchive des Codes herunterzuladen.\n<li class=\"l\"> Standardm\u00e4\u00dfig wird eine eingebaute Datei mimetype.assign bereitgestellt.\n<li class=\"l\"> Die Unterst\u00fctzung f\u00fcr MPTCP (MultiPath TCP) wurde hinzugef\u00fcgt, die standardm\u00e4\u00dfig nicht aktiviert ist.\n<li class=\"l\"> Die Unterst\u00fctzung f\u00fcr die Plattformen GNU\/Hurd und NetBSD 10 wurde verbessert.\n<li class=\"l\"> Die Anzahl der Systemaufrufe, die beim Herstellen von Verbindungen zum Backend durchgef\u00fchrt werden, wurde reduziert.\n<li class=\"l\"> In zuk\u00fcnftigen Releases wird TLSv1.3 als minimal unterst\u00fctzte Standardschl\u00fcsselversion des TLS-Protokolls festgelegt (derzeit ist der Wert von MinProtocol auf TLSv1.2 gesetzt). In Zukunft wird der Handler server.error-handler-404 nur auf die Verarbeitung von 404-Fehlern beschr\u00e4nkt, w\u00e4hrend momentan sowohl 404 als auch 403 bearbeitet werden.    <\/ul>\n<p>Au\u00dferdem ist die Ver\u00f6ffentlichung des HTTP-Servers Apache 2.4.59 zu erw\u00e4hnen, die 21 \u00c4nderungen und die Behebung von drei Schwachstellen beinhaltet:     <\/p>\n<ul>\n<li class=\"l\">CVE-2024-27316 \u2014 eine Schwachstelle, die zu einem Aussch\u00f6pfen des freien Speichers bei einem \u201eContinuation flood\u201c-Angriff f\u00fchrt.\n<li class=\"l\"> CVE-2024-24795, CVE-2023-38709 \u2014 die M\u00f6glichkeit, einen Angriff durch das Aufteilen von HTTP-Antworten auf Frontend-Backend-Systemen durchzuf\u00fchren, die es erm\u00f6glichen, zus\u00e4tzliche Antwortheader einzuf\u00fcgen oder Antworten aufzuteilen, um in die Inhalte anderer Benutzerantworten, die im selben Stream zwischen Frontend und Backend verarbeitet werden, einzudringen.\n<li class=\"l\"> Im Modul mod_cgi wurde der Parameter CGIScriptTimeout hinzugef\u00fcgt, um die Timeout-Zeit f\u00fcr die Ausf\u00fchrung von Skripten festzulegen.\n<li class=\"l\"> In mod_xml2enc wurde die Kompatibilit\u00e4t mit libxml2 2.12.0 und neueren Versionen sichergestellt.\n<li class=\"l\"> In mod_ssl, the standard OpenSSL functions are used for composing lists of certificate authority names when processing the SSLCACertificatePath and SSLCADNRequestPath directives.\n<li class=\"l\"> mod_xml2enc supports XML processing for any MIME types text\/* and XML to prevent data corruption in Microsoft OOXML formats.\n<li class=\"l\"> In the htcacheclean utility, using the -a\/-A options allows iterating through all files for each subdirectory.\n<li class=\"l\"> In mod_ssl, the SSLProxyMachineCertificateFile\/Path directives now allow referencing files that contain certificate authorities' certificates.\n<li class=\"l\"> The documentation for the htpasswd, htdbm, and dbmmanage utilities clarifies that they use hashing, not encryption, for passwords.\n<li class=\"l\"> Support for processing password hashes using the SHA-2 algorithm has been added to htpasswd.\n<li class=\"l\"> In mod_env, overriding system environment variables is permitted.\n<li class=\"l\"> In mod_ldap, HTML data in the ldap-status header has been escaped.\n<li class=\"l\"> In mod_ssl, compatibility with OpenSSL 3 has been improved, and memory freed up by the system is returned.\n<li class=\"l\"> In mod_proxy, TTL can be set for DNS response cache record lifetime configuration.\n<li class=\"l\"> In mod_proxy, support for a third argument has been added to the ProxyRemote parameter to configure credentials for Basic authentication sent to the external proxy.    <\/ul>\n<p>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60990\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u043b\u0435\u0433\u043a\u043e\u0432\u0435\u0441\u043d\u043e\u0433\u043e http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 lighttpd 1.4.76, \u043e\u0440\u0438\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043d\u0430 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u044f \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0430\u043c \u0438 \u0433\u0438\u0431\u043a\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438. Lighttpd \u043f\u0440\u0438\u0433\u043e\u0434\u0435\u043d \u0434\u043b\u044f \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043d\u0430 \u0432\u044b\u0441\u043e\u043a\u043e\u043d\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0438 \u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u043d\u0438\u0437\u043a\u043e\u0435 \u043f\u043e\u0442\u0440\u0435\u0431\u043b\u0435\u043d\u0438\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u0438 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 CPU. \u041a\u043e\u0434 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 \u0421\u0438 \u0438 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 BSD. \u0412 \u043d\u043e\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438: \u041e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 &#171;Continuation flood&#187;, \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0447\u0435\u0440\u0435\u0437 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-115053","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u043b\u0435\u0433\u043a\u043e\u0432\u0435\u0441\u043d\u043e\u0433\u043e http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 lighttpd 1.4.76, \u043e\u0440\u0438\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043d\u0430 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u044f \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0430\u043c \u0438 \u0433\u0438\u0431\u043a\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/reliz-http-serverov-lighttpd-1-4-76-i-apache-httpd-2-4-59\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 Lighttpd 1.4.76 \u0438 Apache httpd 2.4.59 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u043b\u0435\u0433\u043a\u043e\u0432\u0435\u0441\u043d\u043e\u0433\u043e http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 lighttpd 1.4.76, \u043e\u0440\u0438\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043d\u0430 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u044f \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0430\u043c \u0438 \u0433\u0438\u0431\u043a\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/reliz-http-serverov-lighttpd-1-4-76-i-apache-httpd-2-4-59\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-04-14T12:30:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-04-14T12:30:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Release of HTTP servers Lighttpd 1.4.76 and Apache httpd 2.4.59 | ProHoster","description":"The release of the lightweight HTTP server lighttpd 1.4.76 has been announced, focused on high performance, security, standards compliance, and configuration flexibility.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/reliz-http-serverov-lighttpd-1-4-76-i-apache-httpd-2-4-59","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 Lighttpd 1.4.76 \u0438 Apache httpd 2.4.59 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 \u043b\u0435\u0433\u043a\u043e\u0432\u0435\u0441\u043d\u043e\u0433\u043e http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 lighttpd 1.4.76, \u043e\u0440\u0438\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043d\u0430 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u044f \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0430\u043c \u0438 \u0433\u0438\u0431\u043a\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/reliz-http-serverov-lighttpd-1-4-76-i-apache-httpd-2-4-59","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-04-14T12:30:16+00:00","article:modified_time":"2024-04-14T12:30:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"115053","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 22:14:52","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-22 22:14:52","updated":"2026-01-22 22:14:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/115053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=115053"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/115053\/revisions"}],"predecessor-version":[{"id":172909,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/115053\/revisions\/172909"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=115053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=115053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=115053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}