Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 109368 - apache 2.0.55 (version bump)
Summary: apache 2.0.55 (version bump)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Server (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Apache Team - Bugzilla Reports
URL: http://www.apache.org/dist/httpd/Anno...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-10-15 08:00 UTC by Tobias Sager
Modified: 2005-10-22 19:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Sager 2005-10-15 08:00:58 UTC
Apache 2.0.55 is released, fixing several vulnerabilites, some of them already
fixed in portage:

- CAN-2005-2088
  already fixed in bug 98358
- CAN-2005-2491
  already fixed in bug 103554
- CAN-2005-2700
  already fixed in bug 104807
- CAN-2005-2728
  already fixed in bug 102991

No bugzilla entry found for those vulnerabilities:

- No CAN
  proxy_http: If a response contains both Transfer-Encoding and a 
  Content-Length, remove the Content-Length and don't reuse the
  connection.
- CAN-2005-1268
  mod_ssl: Fix off-by-one overflow whilst printing CRL information
  at "LogLevel debug" which could be triggered if configured 
  to use a "malicious" CRL.
  (reported earlier, delayed upstream until this release: see bug 100389)
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-10-15 08:18:16 UTC
(In reply to comment #0)
> No bugzilla entry found for those vulnerabilities:
> 
> - No CAN
>   proxy_http: If a response contains both Transfer-Encoding and a 
>   Content-Length, remove the Content-Length and don't reuse the
>   connection.

This is bug 98358.

> - CAN-2005-1268
>   mod_ssl: Fix off-by-one overflow whilst printing CRL information
>   at "LogLevel debug" which could be triggered if configured 
>   to use a "malicious" CRL.
>   (reported earlier, delayed upstream until this release: see bug 100389)

There is only this one left, and we dismissed it.
Resolving as dupe of bug 98358.

*** This bug has been marked as a duplicate of 98358 ***
Comment 2 Tobias Sager 2005-10-15 08:54:42 UTC
There won't be a 2.0.55 in portage?
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-10-15 10:03:28 UTC
Yes there will, but not for security reasons (current stable is just fine). Feel
free to open another bug for this (or reopen this one and assign it to the
apache team and remove the Gentoo Security product).
Comment 4 Tobias Sager 2005-10-15 10:06:56 UTC
Reopening for apache version bump.
Comment 5 Thomas Stein 2005-10-16 13:21:20 UTC
Hello. 
 
It would be really nice to release an apache 2.0.55 ebuild soon because of this bug: 
http://issues.apache.org/bugzilla/show_bug.cgi?id=15207 
 
regards 
t. 
 
Comment 6 Jernej Kos 2005-10-22 13:30:08 UTC
I would like that as well, since 2.0.55 fixes the following bug:   
http://issues.apache.org/bugzilla/show_bug.cgi?id=34618 
Comment 7 Michael Stewart (vericgar) (RETIRED) gentoo-dev 2005-10-22 19:51:56 UTC
2.0.55 is in CVS.