Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 11 Jul 2025 12:51:03 +0000
From:      bugzilla-noreply@freebsd.org
To:        apache@FreeBSD.org
Subject:   maintainer-feedback requested: [Bug 288148] www/apache24: Security Update to 2.4.64
Message-ID:  <bug-288148-16115-zlCsqQmKZs@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-288148-16115@https.bugs.freebsd.org/bugzilla/>
References:  <bug-288148-16115@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help

Bugzilla Automation <bugzilla@FreeBSD.org> has asked freebsd-apache (Nobody)
<apache@FreeBSD.org> for maintainer-feedback:
Bug 288148: www/apache24: Security Update to 2.4.64
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=288148



--- Description ---
Posting through announce@httpd.apache.org mailing list yesterday:
"Apache HTTP Server 2.4.61 Released"
https://lists.apache.org/thread/7ykzdvkjf27q9rb6mry3q0q061ng9n36
and
"CVE-2024-43204: Apache HTTP Server: SSRF with mod_headers setting Content-Type
header"
https://lists.apache.org/thread/96rsg3t5nrcszwnjmrgqbvp1w9c3t0w9
"CVE-2024-43394: Apache HTTP Server: SSRF on Windows due to UNC paths"
https://lists.apache.org/thread/o98fo2ch4vfcdgzfo1kfpo1q73dqtxfs
"CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable escaping"
https://lists.apache.org/thread/2l2v370h92pyjlvhgb4ols8wk77cw8v5

Patch included, does build for me and is running on FreeBSD 13.5-RELEASE-p2 /
amd64. But I am not sure if I got everything right.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-288148-16115-zlCsqQmKZs>