pkgsrc/www/apache2/patches
adrianp b58cda6746 - Update apache to 2.0.51
- Remove patch-as and patch-ah as they are now outdated and included in the src

- ok'ed snj@, wiz@
- Thanks to epg@ for final check

This version of Apache is principally a bug fix release. Of particular note
is that 2.0.51 addresses five security vulnerabilities:

An input validation issue in IPv6 literal address parsing which can result
in a negative length parameter being passed to memcpy.
[CAN-2004-0786]

A buffer overflow in configuration file parsing could allow a local user to
gain the privileges of a httpd child if the server can be forced to parse a
carefully crafted .htaccess file.
[CAN-2004-0747]

A segfault in mod_ssl which can be triggered by a malicious remote server,
if proxying to SSL servers has been configured.
[CAN-2004-0751]

A potential infinite loop in mod_ssl which could be triggered given
particular timing of a connection abort.
[CAN-2004-0748]

A segfault in mod_dav_fs which can be remotely triggered by an indirect lock
refresh request.
[CAN-2004-0809]

For further details, see http://www.apache.org/dist/httpd/Announcement2.html
and http://apache.rmplc.co.uk/httpd/CHANGES_2.0.
2004-09-20 17:19:33 +00:00
..
patch-aa - Update to apache 2.0.50 2004-07-14 08:28:51 +00:00
patch-ad Avoid hardcoding /usr/pkg in patch files. 2003-07-02 17:54:36 +00:00
patch-ag Updated apache2 to 2.0.44 (patch provided by Eric Gillespie in pkg/20086) 2003-01-28 14:21:56 +00:00
patch-ak Merge packages from the buildlink2 branch back into the main trunk that 2002-08-25 21:50:52 +00:00
patch-al Updated apache to 2.0.40 2002-08-29 14:12:27 +00:00
patch-am
patch-ar - Update apache to 2.0.51 2004-09-20 17:19:33 +00:00