Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 19 Sep 2017 12:29:33 +0000 (UTC)
From:      Ryan Steinmetz <zi@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r450118 - in head/www/apache22: . files
Message-ID:  <201709191229.v8JCTXvO034712@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: zi
Date: Tue Sep 19 12:29:33 2017
New Revision: 450118
URL: https://svnweb.freebsd.org/changeset/ports/450118

Log:
  - Add backport of patch for CVE-2017-9798
  - Bump PORTREVISION
  
  Approved by:	ports-secteam (with hat)
  Security:	76b085e2-9d33-11e7-9260-000c292ee6b8

Added:
  head/www/apache22/files/patch-CVE-2017-9798   (contents, props changed)
Modified:
  head/www/apache22/Makefile

Modified: head/www/apache22/Makefile
==============================================================================
--- head/www/apache22/Makefile	Tue Sep 19 12:23:01 2017	(r450117)
+++ head/www/apache22/Makefile	Tue Sep 19 12:29:33 2017	(r450118)
@@ -2,7 +2,7 @@
 
 PORTNAME=	apache22
 PORTVERSION=	2.2.34
-PORTREVISION?=	0
+PORTREVISION?=	1
 CATEGORIES=	www ipv6
 MASTER_SITES=	APACHE_HTTPD
 DISTNAME=	httpd-${PORTVERSION}

Added: head/www/apache22/files/patch-CVE-2017-9798
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ head/www/apache22/files/patch-CVE-2017-9798	Tue Sep 19 12:29:33 2017	(r450118)
@@ -0,0 +1,21 @@
+CVE-2017-9798
+
+Backport from https://svn.apache.org/viewvc?view=revision&revision=1807655
+
+diff --git a/server/core.c b/server/core.c
+index f61699e..d24542e 100644
+--- server/core.c
++++ server/core.c
+@@ -1809,6 +1809,12 @@ AP_CORE_DECLARE_NONSTD(const char *) ap_limit_section(cmd_parms *cmd,
+             /* method has not been registered yet, but resorce restriction
+              * is always checked before method handling, so register it.
+              */
++            if (cmd->pool == cmd->temp_pool) {
++                /* In .htaccess, we can't globally register new methods. */
++                return apr_psprintf(cmd->pool, "Could not register method '%s' "
++                                   "for %s from .htaccess configuration",
++                                    method, cmd->cmd->name);
++            }
+             methnum = ap_method_register(cmd->pool, method);
+         }
+ 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201709191229.v8JCTXvO034712>