Automatic conversion of the NetBSD pkgsrc CVS module, use with care
Find a file
obache ebadff7698 Update apache to 1.3.41.
Changes with Apache 1.3.41

  *) SECURITY: CVE-2007-6388 (cve.mitre.org)
     mod_status: Ensure refresh parameter is numeric to prevent
     a possible XSS attack caused by redirecting to other URLs.
     Reported by SecurityReason.  [Mark Cox]

Changes with Apache 1.3.40 (not released)

  *) SECURITY: CVE-2007-5000 (cve.mitre.org)
     mod_imap: Fix cross-site scripting issue.  Reported by JPCERT.
     [Joe Orton]

  *) SECURITY: CVE-2007-3847 (cve.mitre.org)
     mod_proxy: Prevent reading past the end of a buffer when parsing
     date-related headers.  PR 41144.
     With Apache 1.3, the denial of service vulnerability applies only
     to the Windows and NetWare platforms.
     [Jeff Trawick]

  *) More efficient implementation of the CVE-2007-3304 PID table
     patch. This fixes issues with excessive memory usage by the
     parent process if long-running and with a high number of child
     process forks during that timeframe. Also fixes bogus "Bad pid"
     errors. [Jim Jagielski, Jeff Trawick]

Changes with Apache 1.3.39

  *) SECURITY: CVE-2006-5752 (cve.mitre.org)
     mod_status: Fix a possible XSS attack against a site with a public
     server-status page and ExtendedStatus enabled, for browsers which
     perform charset "detection".  Reported by Stefan Esser.  [Joe Orton]

  *) SECURITY: CVE-2007-3304 (cve.mitre.org)
     Ensure that the parent process cannot be forced to kill non-child
     processes by checking scoreboard PID data with parent process
     privately stored PID data. [Jim Jagielski]

  *) mime.types: Many updates to sync with IANA registry and common
     unregistered types that the owners refuse to register.  Admins
     are encouraged to update their installed mime.types file.
     pr: 35550, 37798, 39317, 31483 [Roy T. Fielding]

There was no Apache 1.3.38
2008-02-23 05:16:33 +00:00
archivers Not MAKE_JOBS_SAFE. 2008-02-12 11:25:35 +00:00
audio + Rename the "ncursesw" option to "wide-curses" and get rid of the 2008-02-22 16:59:56 +00:00
benchmarks Needs GNU nroff to format catpages with -mandoc. 2008-02-07 13:24:36 +00:00
biology Update nut to 13.2. Should close PR 34466. 2008-01-30 05:43:55 +00:00
bootstrap Try to fix PR pkg/26143 with caution: 2008-01-30 22:57:31 +00:00
cad Update to gerbv-2.0.1. 2008-02-18 22:40:36 +00:00
chat + Remove stuff made unnecessary by the appearance of ncursesw/builtin.mk. 2008-02-22 19:10:38 +00:00
comms +libopensync-plugin-evolution2 2008-02-20 19:13:12 +00:00
converters Add commented out license: GPLv2 or v3. 2008-02-16 13:17:12 +00:00
cross PR 37949: Aleksey Cheusov: USE_TOOLS needs to be fixed in several packages 2008-02-04 19:52:54 +00:00
crosspkgtools Remove empty PLISTs from pkgsrc since revision 1.33 of plist/plist.mk 2007-10-25 16:54:26 +00:00
databases + Name the programs installed by the db(2) package db2_*. 2008-02-21 19:32:23 +00:00
devel - add a patch from debian that fixes a parser bug 2008-02-22 22:13:33 +00:00
distfiles
doc Updated cad/gerbv to 2.0.1 2008-02-23 02:04:13 +00:00
editors + Rename the "ncursesw" option to "wide-curses". This should be supported 2008-02-21 21:56:29 +00:00
emulators Add krb5 module. 2008-02-22 13:36:19 +00:00
filesystems #ifndef out some code which results in SIG_SEGV on NetBSD. See patch-aa. 2008-02-16 01:24:39 +00:00
finance Reset maintainer on his request. 2008-01-19 09:16:17 +00:00
fonts Bump revision for previous. 2008-02-21 02:14:18 +00:00
games I got the velena license wrong and assumed it were public domain, but it 2008-02-20 10:49:16 +00:00
geography revbump due to geography/geos shlib major bump 2008-02-16 01:29:00 +00:00
graphics Update to 1.045. 2008-02-20 11:01:37 +00:00
ham Per the process outlined in revbump(1), perform a recursive revbump 2008-01-18 05:06:18 +00:00
inputmethod Try to fix PLIST problwm with emacs22; leim-list.elc isn't built. 2007-12-22 02:59:59 +00:00
lang Don't use FreeBSD's bluetooth define on DragonFly as well. 2008-02-22 13:03:25 +00:00
licenses I got the velena license wrong and assumed it were public domain, but it 2008-02-20 10:49:16 +00:00
mail Match change to mail/mutt: force sendmail to /usr/sbin/sendmail on 2008-02-22 01:16:58 +00:00
math Update to 2.010709 2008-02-09 22:39:50 +00:00
mbone Fixed invalid lvalue. 2007-12-01 22:03:18 +00:00
meta-pkgs Update to kde3.5.9 2008-02-20 09:45:55 +00:00
misc - merge patch-aa and patch-ab, they patched the same file. 2008-02-22 02:14:53 +00:00
mk +epoll 2008-02-21 19:31:32 +00:00
multimedia Use PKG_BUILD_OPTIONS.vlc instead of PKG_OPTIONS for testing dependencies. 2008-02-23 00:14:51 +00:00
net Get rid of the "gnutls" and "ssl" options and replace with a 2008-02-21 15:50:29 +00:00
news Per the process outlined in revbump(1), perform a recursive revbump 2008-01-18 05:06:18 +00:00
packages
parallel Needs m4 2008-02-09 23:49:27 +00:00
pkgtools pkg_install-20080223: 2008-02-22 21:58:16 +00:00
print Set temporary directory before invoking Ghostscript to avoid random 2008-02-15 15:47:56 +00:00
regress Back out previous. Pointed out by uebayasi@ and martti@. 2007-09-25 10:03:52 +00:00
security Changes 2.1.17: 2008-02-21 17:34:08 +00:00
shells Update osh to 20080109. 2008-01-19 12:08:29 +00:00
sysutils Extend __hpux ifdef to also include __sgi 2008-02-21 01:42:13 +00:00
templates Remove trailing spaces. 2007-10-09 19:19:08 +00:00
textproc + Rename the "ncursesw" option to "wide-curses" and get rid of the 2008-02-22 17:04:34 +00:00
time Honour PKGMANDIR, add missing INSTALLATION_DIRS 2008-02-17 20:30:36 +00:00
wm Add DESTDIR support. 2008-02-23 03:52:30 +00:00
www Update apache to 1.3.41. 2008-02-23 05:16:33 +00:00
x11 Remove no longer needed IRIX hack. 2008-02-22 13:11:33 +00:00
Makefile Fix typo in comment. 2007-06-19 22:30:33 +00:00
pkglocate
README

$NetBSD: README,v 1.18 2005/05/07 22:18:28 wiz Exp $

Please see doc/pkgsrc.txt for information.