Path to this page:
Subject: CVS commit: pkgsrc/www/apache24
From: Takahiro Kambe
Date: 2024-07-03 17:22:22
Message id: 20240703152222.D0D9EFC74@cvs.NetBSD.org
Log Message:
www/apache24: update to 2.4.61
Apache HTTP Server 2.4.61 contains one security fix.
Fixed in Apache HTTP Server 2.4.61
important: Apache HTTP Server: source code disclosure with handlers configured \
via AddType (CVE-2024-39884)
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of
the legacy content-type based configuration of handlers. "AddType" and
similar configuration, under some circumstances where files are requested
indirectly, result in source code disclosure of local content. For example,
PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.61, which fixes this issue.
Reported to security team 2024-07-01
Update 2.4.61 released 2024-07-03
Affects 2.4.60
Files: