Date: Tue, 27 Mar 2018 19:06:54 +0000 From: "Philip M. Gollucci" <pgollucci@p6m7g8.com> To: Vincent Hoffman-Kazlauskas <vince@unsane.co.uk> Cc: freebsd-ports@freebsd.org Subject: Re: Removal of www/apache22 Message-ID: <CACM2dAan5skfR1mrQRhVGgOcLrQS_We_WR9KZqrLJMXTzZG_ew@mail.gmail.com> In-Reply-To: <7a0002af-57f4-c5dd-b43e-402f3a0913eb@unsane.co.uk> References: <f013fd38b474b5547dfd6b6e7e21dbce@freebsd.org> <7a0002af-57f4-c5dd-b43e-402f3a0913eb@unsane.co.uk>
next in thread | previous in thread | raw e-mail | index | archive | help
I support removal On Tue, Mar 27, 2018 at 10:11 AM Vincent Hoffman-Kazlauskas < vince@unsane.co.uk> wrote: > > > On 27/03/2018 13:52, Bernard Spil wrote: > > Hi all, > > > > Just noticed that the Apache project has removed the patches they had > > for 2.2.34. > > > > http://www.apache.org/dist/httpd/patches/apply_to_2.2.34/ > > > > Combined with the security update of 2.4 branch to 2.4.33 leads me to > > believe that Apache 2.2 is now vulnerable and no patches will be > provided. > > > > If someone wishes to step up and get patches for 2.2 from e.g. RedHat, > > we may be able to keep the port alive for a bit longer. If no one steps > > up, I see no other way forward than to delete the port as indicated by > > the DEPRECATED variable and expiration date 2017-07-01 since July 2016. > > > > While I agree that apache 2.2 is now firmly dead, they moved the patches > for 2.2.34 to > https://archive.apache.org/dist/httpd/patches/apply_to_2.2.34/ , however > no new patches for the recent CVEs were added. > > > Vince > > > > > Cheers, > > > > Bernard. > > _______________________________________________ > > freebsd-ports@freebsd.org mailing list > > https://lists.freebsd.org/mailman/listinfo/freebsd-ports > > To unsubscribe, send any mail to "freebsd-ports-unsubscribe@freebsd.org" > _______________________________________________ > freebsd-ports@freebsd.org mailing list > https://lists.freebsd.org/mailman/listinfo/freebsd-ports > To unsubscribe, send any mail to "freebsd-ports-unsubscribe@freebsd.org" > -- --------------------------------------------------------------------------------- 4096R/D21D2752 <http://pgp.mit.edu/pks/lookup?op=get&search=0xF699A450D21D2752> ECDF B597 B54B 7F92 753E E0EA F699 A450 D21D 2752 Philip M. Gollucci (pgollucci@p6m7g8.com) c: 703.336.9354 Member, Apache Software Foundation Committer, FreeBSD Foundation Consultant, P6M7G8 Inc. Director Cloud Technology, Capital One What doesn't kill us can only make us stronger; Except it almost kills you.
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CACM2dAan5skfR1mrQRhVGgOcLrQS_We_WR9KZqrLJMXTzZG_ew>