From owner-cvs-ports@FreeBSD.ORG Wed Sep 15 16:54:37 2004 Return-Path: Delivered-To: cvs-ports@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DFD9916A4CE; Wed, 15 Sep 2004 16:54:37 +0000 (GMT) Received: from repoman.freebsd.org (repoman.freebsd.org [216.136.204.115]) by mx1.FreeBSD.org (Postfix) with ESMTP id D154B43D2F; Wed, 15 Sep 2004 16:54:37 +0000 (GMT) (envelope-from clement@FreeBSD.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.12.11/8.12.11) with ESMTP id i8FGsb6H087535; Wed, 15 Sep 2004 16:54:37 GMT (envelope-from clement@repoman.freebsd.org) Received: (from clement@localhost) by repoman.freebsd.org (8.12.11/8.12.11/Submit) id i8FGsbDV087534; Wed, 15 Sep 2004 16:54:37 GMT (envelope-from clement) Message-Id: <200409151654.i8FGsbDV087534@repoman.freebsd.org> From: Clement Laforet Date: Wed, 15 Sep 2004 16:54:37 +0000 (UTC) To: ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org X-FreeBSD-CVS-Branch: HEAD Subject: cvs commit: ports/www/apache2 Makefile Makefile.doc patch-secfix-modules:dav:fs:lock.c patch-secfix-srclib:apr-util:test:testuri.c X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Sep 2004 16:54:38 -0000 clement 2004-09-15 16:54:37 UTC FreeBSD ports repository Modified files: www/apache2 Makefile Makefile.doc Makefile.modules.3rd Added files: www/apache2/files patch-secfix-modules:dav:fs:lock.c patch-secfix-server:utils.c patch-secfix-srclib:apr-util:test:testuri.c Log: Security fixes [1]: *) SECURITY: CAN-2004-0786 (cve.mitre.org) Fix an input validation issue in apr-util which could be triggered by malformed IPv6 literal addresses. [Joe Orton] *) SECURITY: CAN-2004-0747 (cve.mitre.org) Fix buffer overflow in expansion of environment variables in configuration file parsing. [Andr Malo] *) SECURITY: CAN-2004-0809 (cve.mitre.org) mod_dav_fs: Fix a segfault in the handling of an indirect lock refresh. PR 31183. [Joe Orton] - Update documentation (finally!) and fix WITH__MODULES for special modules like LDAP or SSL [2] Noticed by: nectar [1] Requested by: Emile Heitor [2] Approved by: portmgr (marcus) Revision Changes Path 1.199 +17 -3 ports/www/apache2/Makefile 1.10 +23 -18 ports/www/apache2/Makefile.doc 1.11 +2 -2 ports/www/apache2/Makefile.modules.3rd 1.1 +46 -0 ports/www/apache2/files/patch-secfix-modules:dav:fs:lock.c (new) 1.1 +132 -0 ports/www/apache2/files/patch-secfix-server:utils.c (new) 1.1 +33 -0 ports/www/apache2/files/patch-secfix-srclib:apr-util:test:testuri.c (new)