Based on the CVE, apache2 in Dapper *is* vulnerable, but the backporting of this fix isn't trivial. Emgent, can you describe your testing environment? That would help in testing the Dapper backport.
** Changed in: apache2 (Ubuntu Dapper) Status: New => Confirmed -- CVE-2008-2364 Apache2 mod_proxy_http.c DOS https://bugs.launchpad.net/bugs/239894 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs