From owner-cvs-ports@FreeBSD.ORG Sun Aug 31 23:00:27 2008 Return-Path: Delivered-To: cvs-ports@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B41331065672; Sun, 31 Aug 2008 23:00:27 +0000 (UTC) (envelope-from clement@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [IPv6:2001:4f8:fff6::29]) by mx1.freebsd.org (Postfix) with ESMTP id A1CFE8FC18; Sun, 31 Aug 2008 23:00:27 +0000 (UTC) (envelope-from clement@FreeBSD.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.14.2/8.14.2) with ESMTP id m7VN0RkV025927; Sun, 31 Aug 2008 23:00:27 GMT (envelope-from clement@repoman.freebsd.org) Received: (from clement@localhost) by repoman.freebsd.org (8.14.2/8.14.1/Submit) id m7VN0RJV025926; Sun, 31 Aug 2008 23:00:27 GMT (envelope-from clement) Message-Id: <200808312300.m7VN0RJV025926@repoman.freebsd.org> From: Clement Laforet Date: Sun, 31 Aug 2008 23:00:27 +0000 (UTC) To: ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org X-FreeBSD-CVS-Branch: HEAD Cc: Subject: cvs commit: ports/www/apache22 Makefile pkg-plist ports/www/apache22/files apache22.sh.in patch-CVE-2008-2939 X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 31 Aug 2008 23:00:27 -0000 clement 2008-08-31 23:00:27 UTC FreeBSD ports repository Modified files: www/apache22 Makefile pkg-plist www/apache22/files apache22.sh.in Added files: www/apache22/files patch-CVE-2008-2939 Log: - Yet Another Plist Fix [1] - Completely shut up rc.d script when no profiles are enabled (add add support to disable profiles) [2] - Fix CVE-2008-2939 for mod_proxy_ftp (XSS attacks when using wildcards in the path of the FTP URL) - Add "apache22_fib" to start apache22 prefixed by "setfib -F ${apache22_fib}", so apache can use an alternate network view (not carefully tested yet) - Revert previous patch to "fix" missing rc.d scripts. It actually breaks profiles. - Bump PORTREVISION PR: ports/126670 [1], ports/116627 [2] Submitted by: Joseph S. Atkinson [1], Eygene Ryabinkin [2] Security: CVE-2008-2939 Special thanks to: pgollucci@ Revision Changes Path 1.222 +5 -3 ports/www/apache22/Makefile 1.6 +43 -2 ports/www/apache22/files/apache22.sh.in 1.1 +11 -0 ports/www/apache22/files/patch-CVE-2008-2939 (new) 1.89 +3 -2 ports/www/apache22/pkg-plist