New apache packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix potential security issues:
* If a request contains both Transfer-Encoding and Content-Length headers, remove the Content-Length, mitigating some HTTP Request Splitting/Spoofing attacks.
* Added TraceEnable [on|off|extended] per-server directive to alter the behavior of the TRACE method.
It's hard to say how much real-world impact these have, as there's no more information about that in the announcement. The original Apache nnounement can be read here:
http://www.apache.org/dist/httpd/Announcement1.3.htmlNote that if you use mod_ssl, you will also need a new mod_ssl package. These have been provided for the same releases of Slackware.