Path to this page:
Subject: CVS commit: [pkgsrc-2012Q4] pkgsrc/www/apache24
From: Matthias Scheler
Date: 2013-02-27 10:37:43
Message id: 20130227093743.A9AF7175DD@cvs.netbsd.org
Log Message:
Pullup ticket #4081 - requested by ryoon
www/apache24: security update
Revisions pulled up:
- www/apache24/Makefile 1.15 via patch
- www/apache24/PLIST 1.9
- www/apache24/distinfo 1.7
- www/apache24/patches/patch-ad 1.2
- www/apache24/patches/patch-ag 1.2
- www/apache24/patches/patch-modules_ssl_ssl__private.h 1.3
---
Module Name: pkgsrc
Committed By: ryoon
Date: Mon Feb 25 21:16:38 UTC 2013
Modified Files:
pkgsrc/www/apache24: Makefile PLIST distinfo
pkgsrc/www/apache24/patches: patch-ad patch-ag
patch-modules_ssl_ssl__private.h
Log Message:
Update to 2.4.4
Changelog:
Fix the following security bugs.
SECURITY: CVE-2012-3499 (cve.mitre.org) Various XSS flaws due to \
unescaped hostnames and URIs HTML output in mod_info, mod_status, mod_imagemap, \
mod_ldap, and mod_proxy_ftp.
SECURITY: CVE-2012-4558 (cve.mitre.org) XSS in mod_proxy_balancer manager \
interface.
Files: