Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 140543 - net-www/apache - security cleanup needed
Summary: net-www/apache - security cleanup needed
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal
Assignee: Apache Team - Bugzilla Reports
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-07-15 12:23 UTC by Jakub Moc (RETIRED)
Modified: 2007-01-09 14:39 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jakub Moc (RETIRED) gentoo-dev 2006-07-15 12:23:21 UTC
net-www/apache-1.3.34-r10: vulnerable via glsa(200602-03) ( ver-rev < 2.0.55-r1 && not ( ver = 2.0.54 && ver-rev => 2.0.54-r16 ) && ver-rev not = 1.3.34-r2 && not ( ver = 1.3.34 && ver-rev => 1.3.34-r11 ) ), affects ('alpha', 'amd64', 'arm', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 's390', 'sh', 'sparc', 'x86')

net-www/mod_auth_pgsql-0.9.12-r1: vulnerable via glsa(200601-05) ( ver < 2.0.3 ), affects ('amd64', 'x86')
net-www/mod_auth_pgsql-2.0.2-r2: vulnerable via glsa(200601-05) ( ver < 2.0.3 ), affects ('amd64', 'ppc', 'sparc', 'x86')

www-apache/libapreq2-2.04.03: vulnerable via glsa(200604-08) ( ver < 2.07 ), affects ('amd64', 'x86')
www-apache/libapreq2-2.06: vulnerable via glsa(200604-08) ( ver < 2.07 ), affects ('alpha', 'amd64', 'ppc', 'sparc', 'x86')

Please, clean up the above. Thanks! arm, s390, sh still needs to stabilize net-www/apache-1.3.34-r11, CCing.
Comment 1 Michael Stewart (vericgar) (RETIRED) gentoo-dev 2006-08-16 11:55:35 UTC
I just removed mod_auth_pgsql-2.0.2-r2.

mod_auth_pgsql-0.9.12 is the only version that works with apache 1.3, so I am hesitant to remove it. The security advisory doesn't mention 0.9.12 at all, so it might be that it's not affected (this needs to be looked into however)
Comment 2 Michael Stewart (vericgar) (RETIRED) gentoo-dev 2006-08-16 13:25:24 UTC
libapreq2 is herd perl, not apache.
Comment 3 Yuval Yaari (RETIRED) gentoo-dev 2006-08-20 07:14:30 UTC
Done.
Removed www-apache/libapreq2-2.04.03 and www-apache/libapreq2-2.06.
Removing perl@g.o from CC now, please re-add if needed.
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2006-09-02 16:39:18 UTC
(In reply to comment #1)
> mod_auth_pgsql-0.9.12 is the only version that works with apache 1.3, so I am
> hesitant to remove it. The security advisory doesn't mention 0.9.12 at all, so
> it might be that it's not affected (this needs to be looked into however)

@security: Can you fix the GLSA-200601-05, please?  

Comment 5 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-09-03 12:15:58 UTC
> @security: Can you fix the GLSA-200601-05, please?  
> 

that's now corrected in CVS, thanks
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-04 07:39:17 UTC
Removing security from CC. Please readd us if needed.
Comment 7 Luca Longinotti (RETIRED) gentoo-dev 2006-09-30 08:06:28 UTC
arm, s390, sh: please stable net-www/apache-1.3.34-r14, thanks!
Best regards, CHTEKK.
Comment 8 SpanKY gentoo-dev 2006-11-11 20:32:48 UTC
done
Comment 9 Luca Longinotti (RETIRED) gentoo-dev 2006-12-02 16:04:58 UTC
Closing!
Best regards, CHTEKK.
Comment 10 Jakub Moc (RETIRED) gentoo-dev 2006-12-03 16:39:22 UTC
Uhm, would help to punt the vulnerable versions before closing this one ;)


net-www/apache-1.3.34-r10: vulnerable via glsa(200602-03) ( ver-rev < 2.0.55-r1 && not ( ver = 2.0.54 && ver-rev >= 2.0.54-r16 ) && ver-rev not = 1.3.34-r2 && not ( ver = 1.3.34 && ver-rev >= 1.3.34-r11 ) && ver not = 1.3.37 ), affects ('alpha', 'amd64', 'arm', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 's390', 'sh', 'sparc', 'x86')
net-www/apache-1.3.34-r10: vulnerable via glsa(200608-01) ( ver-rev < 2.0.58-r2 && not ( ver = 1.3.34 && ver-rev >= 1.3.34-r14 ) && ver not = 1.3.37 ), affects ('alpha', 'amd64', 'arm', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 's390', 'sh', 'sparc', 'x86')
net-www/apache-1.3.34-r11: vulnerable via glsa(200608-01) ( ver-rev < 2.0.58-r2 && not ( ver = 1.3.34 && ver-rev >= 1.3.34-r14 ) && ver not = 1.3.37 ), affects ('alpha', 'amd64', 'arm', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 's390', 'sh', 'sparc', 'x86')
net-www/apache-2.0.54-r31: vulnerable via glsa(200608-01) ( ver-rev < 2.0.58-r2 && not ( ver = 1.3.34 && ver-rev >= 1.3.34-r14 ) && ver not = 1.3.37 ), affects ('alpha', 'amd64', 'arm', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 's390', 'sh', 'sparc', 'x86')
net-www/apache-2.0.58: vulnerable via glsa(200608-01) ( ver-rev < 2.0.58-r2 && not ( ver = 1.3.34 && ver-rev >= 1.3.34-r14 ) && ver not = 1.3.37 ), affects ('alpha', 'amd64', 'arm', 'hppa', 'ia64', 'mips', 'ppc', 'ppc64', 's390', 'sh', 'sparc', 'x86', 'x86-fbsd')
Comment 11 Bryan Østergaard (RETIRED) gentoo-dev 2007-01-09 14:39:52 UTC
Old apache versions removed.