ports/47672: commit references a PR

dfilter service dfilter at FreeBSD.ORG
Wed Dec 9 23:50:03 UTC 2009


The following reply was made to PR ports/47672; it has been noted by GNATS.

From: dfilter at FreeBSD.ORG (dfilter service)
To: bug-followup at FreeBSD.org
Cc:  
Subject: Re: ports/47672: commit references a PR
Date: Wed,  9 Dec 2009 23:48:14 +0000 (UTC)

 pgollucci    2009-12-09 23:48:01 UTC
 
   FreeBSD ports repository
 
   Modified files:
     www/apache22         Makefile distinfo 
   Log:
   - Update to 2.2.14
   - With hat apache@
   
   Note: The 3 CVE's are a no-op for the FreeBSD port --
   
   date: 2009/08/25 05:33:03;  author: kuriyama;  state: Exp;  lines: +0 -0
   (Forced commit)
   
   - 2.2.13 (acutally 2.2.12) includes fixes for several CVEs. [1]
     but in our ports tree, APR related ones (CVE-2009-0023,
     CVE-2009-1955, CVE-2009-1956) were already backported in 2.2.11_5.
   
   References:     http://www.apache.org/dist/httpd/CHANGES_2.2.12 [1]
   
   Changes:
   ---------
   
     *) SECURITY: CVE-2009-2699 (cve.mitre.org)
        Fixed in APR 1.3.9.  Faulty error handling in the Solaris pollset support
        (Event Port backend) which could trigger hangs in the prefork and event
        MPMs on that platform.  PR 47645.  [Jeff Trawick]
   
     *) SECURITY: CVE-2009-3095 (cve.mitre.org)
        mod_proxy_ftp: sanity check authn credentials.
        [Stefan Fritsch <sf fritsch.de>, Joe Orton]
   
     *) SECURITY: CVE-2009-3094 (cve.mitre.org)
        mod_proxy_ftp: NULL pointer dereference on error paths.
        [Stefan Fritsch <sf fritsch.de>, Joe Orton]
   
     *) mod_proxy_scgi: Backport from trunk. [André Malo]
   
     *) mod_ldap: Don't try to resolve file-based user ids to a DN when AuthLDAPURL
        has been defined at a very high level.  PR 45946.  [Eric Covener]
   
     *) htcacheclean: 19 ways to fail, 1 error message. Fixed. [Graham Leggett]
   
     *) mod_ldap: Bring the LDAPCacheEntries and LDAPOpCacheEntries
        usage() in synch with the manual and the implementation (0 and -1
        both disable the cache). [Eric Covener]
   
     *) mod_ssl: The error message when SSLCertificateFile is missing should
        at least give the name or position of the problematic virtual host
        definition. [Stefan Fritsch sf sfritsch.de]
   
     *) htdbm: Fix possible buffer overflow if dbm database has very
        long values.  PR 30586 [Dan Poirier]
   
     *) Add support for HTTP PUT to ab. [Jeff Barnes <jbarnesweb yahoo.com>]
   
     *) mod_ssl: Fix SSL_*_DN_UID variables to use the 'userID' attribute
        type.  PR 45107.  [Michael Ströder <michael stroeder.com>,
        Peter Sylvester <peter.sylvester edelweb.fr>]
   
     *) mod_cache: Add CacheIgnoreURLSessionIdentifiers directive to ignore
        defined session identifiers encoded in the URL when caching.
        [Ruediger Pluem]
   
     *) mod_mem_cache: fix seg fault under load due to pool concurrency problem
        PR: 47672 [Dan Poirier <poirier pobox.com>]
   
     *) mod_autoindex: Correctly create an empty cell if the description
        for a file is missing. PR 47682 [Peter Poeml <poeml suse.de>]
   
   Revision  Changes    Path
   1.244     +1 -1      ports/www/apache22/Makefile
   1.78      +3 -3      ports/www/apache22/distinfo
 _______________________________________________
 cvs-all at freebsd.org mailing list
 http://lists.freebsd.org/mailman/listinfo/cvs-all
 To unsubscribe, send any mail to "cvs-all-unsubscribe at freebsd.org"
 



More information about the freebsd-ports-bugs mailing list