[Bug 288148] www/apache24: Security Update to 2.4.64

From: <bugzilla-noreply_at_freebsd.org>
Date: Fri, 11 Jul 2025 12:51:03 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=288148

            Bug ID: 288148
           Summary: www/apache24: Security Update to 2.4.64
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: https://downloads.apache.org/httpd/CHANGES_2.4
                OS: Any
            Status: New
          Keywords: patch, security
          Severity: Affects Many People
          Priority: ---
         Component: Individual Port(s)
          Assignee: apache@FreeBSD.org
          Reporter: fabian@wenks.ch
          Assignee: apache@FreeBSD.org
             Flags: maintainer-feedback?(apache@FreeBSD.org)

Created attachment 262048
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=262048&action=edit
git diff patch to update httpd 2.4.64

Posting through announce@httpd.apache.org mailing list yesterday:
"Apache HTTP Server 2.4.61 Released"
https://lists.apache.org/thread/7ykzdvkjf27q9rb6mry3q0q061ng9n36
and
"CVE-2024-43204: Apache HTTP Server: SSRF with mod_headers setting Content-Type
header"
https://lists.apache.org/thread/96rsg3t5nrcszwnjmrgqbvp1w9c3t0w9
"CVE-2024-43394: Apache HTTP Server: SSRF on Windows due to UNC paths"
https://lists.apache.org/thread/o98fo2ch4vfcdgzfo1kfpo1q73dqtxfs
"CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable escaping"
https://lists.apache.org/thread/2l2v370h92pyjlvhgb4ols8wk77cw8v5

Patch included, does build for me and is running on FreeBSD 13.5-RELEASE-p2 /
amd64. But I am not sure if I got everything right.

-- 
You are receiving this mail because:
You are the assignee for the bug.