Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 342055 - www-servers/apache-2.2.17: Version bump
Summary: www-servers/apache-2.2.17: Version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All All
: High enhancement with 3 votes (vote)
Assignee: Apache Team - Bugzilla Reports
URL: http://www.apache.org/dist/httpd/CHAN...
Whiteboard:
Keywords:
Depends on:
Blocks: 347782 354297
  Show dependency tree
 
Reported: 2010-10-21 18:47 UTC by Hanno Böck
Modified: 2011-02-18 17:31 UTC (History)
11 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
apache-2.2.17.ebuild (apache-2.2.17.ebuild,2.62 KB, text/plain)
2011-02-09 18:31 UTC, Chris Smith
Details
tarball for apache-2.2.17 (gentoo-apache-2.2.17-20110209.tar.bz2,62.16 KB, application/octet-stream)
2011-02-09 18:33 UTC, Chris Smith
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2010-10-21 18:47:38 UTC
apache webpage lists it as a security update, though not citing which changes are security relevant.
According to
http://www.apache.org/dist/httpd/CHANGES_2.2.17
These sound like possibly security relevant:
  *) core: check symlink ownership if both FollowSymlinks and
     SymlinksIfOwnerMatch are set [Nick Kew]
  *) rotatelogs: Fix possible buffer overflow if admin configures a
     mongo log file path. [Jeff Trawick]
  *) mod_ssl: Do not do overlapping memcpy. PR 45444 [Joe Orton]
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2010-10-22 06:50:29 UTC
http://www.apache.org/dist/httpd/Announcement2.2.html lists three security fixes.

    * CVE-2010-1623:  Fix a denial of service attack against apr_brigade_split_line().
    * CVE-2009-3560, CVE-2009-3720: Fix two buffer over-read flaws in the bundled copy of expat which could cause applications to crash while parsing specially-crafted XML documents.

The apache-2.2.16 ebuild does appear to bundle vulnerable versions of apr-util and expat.
Comment 2 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2010-10-23 12:06:24 UTC
(In reply to comment #1)
> The apache-2.2.16 ebuild does appear to bundle vulnerable versions of apr-util
> and expat.

No. www-servers/apache doesn't use any bundled libraries.
Comment 3 Milos Ivanovic 2010-10-27 15:12:12 UTC
Bump the version anyway :-)
Comment 4 Milos Ivanovic 2010-12-18 11:33:40 UTC
Any progress regarding this version bump?
Comment 5 Agostino Sarubbo gentoo-dev 2011-01-24 15:51:33 UTC
@apache

There are reasons why there is a delay of three months of this bump in tree?

Dropping if it was not focussed on a possible security bug, I think that it is important software and a bump has priority
Comment 6 Chris Smith 2011-02-09 17:46:59 UTC
2.2.17 released almost 4 months ago... listed as security and bugfix release
Comment 7 Chris Smith 2011-02-09 18:31:23 UTC
Created attachment 261943 [details]
apache-2.2.17.ebuild

Experimental ebuild for Apache-2.2.17, works here, no guarantees. Requires the tarball (just re-rolled the current gentoo patchset with no internal changes) which I will also upload, plus you must also bump app-admin/apache-tools-2.2.17 (I used a simple rename in my local portage dir).
Comment 8 Chris Smith 2011-02-09 18:33:06 UTC
Created attachment 261949 [details]
tarball for apache-2.2.17

place this tarball in distfiles for apache-2.2.17
Comment 9 Paweł Jastrzębski 2011-02-11 19:06:22 UTC
Bump is needed ASAP.
*) mod_ssl: Do not do overlapping memcpy. PR 45444 [Joe Orton]

~amd64 systems with Apache 2.2.16-r1 + glibc 2.13 can't use mod_ssl now.
Comment 10 Attila Jecs 2011-02-15 03:53:20 UTC
yes, please add it to the tree, i can't use ssl.

or next time hold back app-breaking updates of glibc

thx.

~amd64/no-multilib
Comment 11 chris salch 2011-02-16 18:11:51 UTC
I can confirm that this build appears to fix my own ssl problems (amd64).  Is there an eta on actually releasing it?
Comment 12 chris salch 2011-02-16 19:36:07 UTC
(In reply to comment #11)
> I can confirm that this build appears to fix my own ssl problems (amd64).  Is
> there an eta on actually releasing it?
> 

I'll amend that, the bug is still there just less pervasive.
Comment 13 chris salch 2011-02-16 19:38:46 UTC
(In reply to comment #12)
> (In reply to comment #11)
> > I can confirm that this build appears to fix my own ssl problems (amd64).  Is
> > there an eta on actually releasing it?
> > 
> 
> I'll amend that, the bug is still there just less pervasive.
> 

drat, turns out you also nee apache-tools-2.2.17 to install this, missed that.
Comment 14 Alexey Sychev 2011-02-18 06:55:36 UTC
When can we expect to add this version to the tree?
Comment 15 Benedikt Böhm (RETIRED) gentoo-dev 2011-02-18 17:31:07 UTC
2.2.17 in portage