9 Commits

Author SHA1 Message Date
Natanael Copa
8c814a95fd main/apache2: security upgrade to 2.2.23 (CVE-2012-2687,CVE-2012-0883)
fixes #1425
2012-11-16 08:42:49 +00:00
Natanael Copa
eb6bfe8b90 main/apache2: security upgrade to 2.2.22 (CVE-2012-0021, CVE-2012-0031, CVE-2012-0053, CVE-2011-3368, CVE-2011,3607)
low: mod_log_config crash CVE-2012-0021
low: scoreboard parent DoS CVE-2012-0031
moderate: error responses can expose cookies CVE-2012-0053
moderate: mod_proxy reverse proxy exposure CVE-2011-3368
low: mod_setenvif .htaccess privilege escalation CVE-2011-3607

This release also include the previosly patched:
moderate: mod_proxy reverse proxy exposure CVE-2011-4317

fixes #985
2012-02-01 08:03:40 +00:00
Leonardo Arena
fc62f60822 main/apache2: security hotfix #844 (CVE-2011-4317)
(cherry picked from commit 9f987f8ab1533bc6cdb29f36f144101bae980efe)
2011-11-28 13:05:45 +00:00
Natanael Copa
9b66b111e7 main/apache2: security upgrade to 2.2.21 (CVE-2011-3348)
fixes #770
fixes #771
(cherry picked from commit 2bd7604b97b22478cafae3519efd0ff42c4eef20)
2011-10-17 19:19:48 +00:00
Natanael Copa
918f5782d5 main/apache2: security upgrade to 2.2.20 (CVE-2011-3192)
(cherry picked from commit 14d8b3ce0d0c7c58bf88f7497905e44f222409a7
and 169b985e5d05eba2054661b09fa9d1c5c32bc102)
(cherry picked from commit 5fb412b0ce117306582023c2852bb72d612ff5d5)

Conflicts:

	main/apache2/APKBUILD
2011-10-17 19:14:50 +00:00
Matt Smith
6f98e9ce6b main/apache2: fix worker and itk mpms, added itk configuration
The trouble I had while debugging this issue had to do with how I was attempting to install packages from aports.  Thanks to Timo and Natanael for getting me back on the right track.

Once I was able to successfully install apache2 from aports, I got down to business.  I have an updated APKBUILD that seems to fix the issue of having extra modules being compiled in with the alternative "itk" and "worker" MPMs; "{httpd,httpd.itk,httpd.worker} -l" output looks correct, and they all start without modifications to /etc/apache2/httpd.conf, so I believe this issue to be resolved.

I also added the itk configuration to httpd.conf.
fixes #473
(cherry picked from commit f5f96266feb28f91e79456046ef2bcf850a00c50)
2010-12-09 13:27:14 +00:00
Natanael Copa
e12e8baa59 main/apache2: upgrade to 2.2.17 2010-10-23 08:52:21 +00:00
Natanael Copa
2276aee4cf main/apache2: move ldapconfig to -ldap subpackage
and fix -dev dependencies

fixes #401
2010-08-10 13:43:00 +00:00
Natanael Copa
c82268523e main/apache2: moved from testing
fixes #392
2010-08-10 12:19:19 +00:00