From owner-freebsd-www Mon Jul 1 11:27:20 2002 Delivered-To: freebsd-www@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 87E0A37B405; Mon, 1 Jul 2002 11:27:16 -0700 (PDT) Received: from overcee.wemm.org (12-232-114-102.client.attbi.com [12.232.114.102]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6E14643E0A; Mon, 1 Jul 2002 11:27:15 -0700 (PDT) (envelope-from peter@wemm.org) Received: from wemm.org (localhost [127.0.0.1]) by overcee.wemm.org (Postfix) with ESMTP id 00DEA3915; Mon, 1 Jul 2002 11:27:22 -0700 (PDT) (envelope-from peter@wemm.org) X-Mailer: exmh version 2.5 07/13/2001 with nmh-1.0.4 To: Wolfram Schneider Cc: Kris Kennaway , admins@FreeBSD.ORG, www@FreeBSD.ORG, so@FreeBSD.ORG Subject: Re: apache upgrades In-Reply-To: <20020701195912.A7511@freno.cs.tu-berlin.de> Date: Mon, 01 Jul 2002 11:27:21 -0700 From: Peter Wemm Message-Id: <20020701182722.00DEA3915@overcee.wemm.org> Sender: owner-freebsd-www@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Wolfram Schneider wrote: > On 2002-07-01 10:46:44 -0700, Kris Kennaway wrote: > > On Mon, Jul 01, 2002 at 07:39:52PM +0200, Wolfram Schneider wrote: > > > On 2002-07-01 10:27:41 -0700, Kris Kennaway wrote: > > > > I'm just in the process of updating apache on freefall, hub and www. > > > > I might have broken things, but frankly I don't care because I've > > > > asked twice already and apparently no-one else with root cares. I'm > > > > pretty annoyed about this. > > > > > > What is wrong with the apache on freefall, hub and www? All > > > machines runs an up-to-date apache. > > > > No they didn't, they still had very old versions of the port installed. > > Wrong. All versions where updated, as I told you in private > mail days ago (with cc: to admins, webmaster and security-officer). > > To get the server build time, please > use the apache option -v (/usr/local/sbin/httpd -v). > > -Wolfram For reference, here is the email in question: == begin == Subject: Re: Reminder: URGENT APACHE UPGRADES NEEDED From: Wolfram Schneider Date: Sat, 22 Jun 2002 23:26:59 +0200 To: Kris Kennaway Cc: admins@FreeBSD.ORG, webmaster@FreeBSD.ORG, so@FreeBSD.ORG On 2002-06-22 12:26:52 -0700, Kris Kennaway wrote: > The following machines have versions of apache that are claimed to be > vulnerable to a remote root exploit (for which a FreeBSD exploit has > been published). They need to be upgraded immediately. > > freefall > www > axp0 (kerberos seems to be b0rked on this machine, otherwise I would > have fixed it myself) > > Who will fix these? I updated apache on freefall, hub and nwww some hours ago. Hope that helps. Sorry for the late answer, I'm just back from a 2 week vacation without Internet access. -Wolfram -- Wolfram Schneider http://wolfram.schneider.org == end == Kris, can you put the old apache back on freefall? You've pretty badly broken it. Or, Wolfram, do you have the build handy? Cheers, -Peter -- Peter Wemm - peter@wemm.org; peter@FreeBSD.org; peter@yahoo-inc.com "All of this is for nothing if we don't go to the stars" - JMS/B5 To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-www" in the body of the message