Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 25110 - [SECURITY] apache update: 1.3.28
Summary: [SECURITY] apache update: 1.3.28
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Highest critical
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-07-23 04:20 UTC by Torgeir Hansen
Modified: 2011-10-30 22:41 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Torgeir Hansen 2003-07-23 04:20:26 UTC
a new version of apache 1.3 was released a couple of days ago; but no updated 
ebuild yet:
http://www.securityfocus.com/bid/8226
http://www.apache.org/dist/httpd/CHANGES_1.3

I'm marking it as critical as this IS a security-update that has not been taken 
care of by whoever is maintaining it yet! :/
Comment 1 Patrick Kursawe (RETIRED) gentoo-dev 2003-07-23 04:23:59 UTC
Is there something I missed or is the SECURITY stuff in the CHANGES file just for OS/2 and Win32?
Comment 2 Patrick Kursawe (RETIRED) gentoo-dev 2003-07-23 04:27:16 UTC
Ok, found what I was looking for on http://www.apache.org/dist/httpd/Announcement.html
Comment 3 Donny Davies (RETIRED) gentoo-dev 2003-07-23 11:11:59 UTC
added.
Comment 4 Martin Holzer (RETIRED) gentoo-dev 2003-07-23 12:54:08 UTC
aliz: could you please send out GLSA
Comment 5 Torgeir Hansen 2003-07-26 11:44:25 UTC
from /usr/portage/net-www/apache/ChangeLog:
--
  23 Jul 2003; Donny Davies <woodchip@gentoo.org> apache-1.3.28.ebuild:
  Security update.  Will un-arch-mask after a few "it works for me" reports.
--

#1: it works
#2: security updates should really not have been marked as experimental, especially when I've (and probably others) been waiting for this update since tuesday.. (!!) :P

Comment 6 Martin Holzer (RETIRED) gentoo-dev 2003-07-28 13:47:07 UTC
please don't close this, GLSA has to be sent out and package has to be marked stable
Comment 7 Corvus 2003-07-30 01:06:43 UTC
please someone unmask mod_ssl-2.8.15 then. 
the 2.8.14 still depends on th 1.3.27 apache and my  
emerge -uD world kept up and donwgrading 
apache every 2nd time I run it 
Comment 8 Donny Davies (RETIRED) gentoo-dev 2003-08-05 21:06:23 UTC
this is all taken care of... the bug is fixed and people are getting
the proper versions.

oh, and mod_ssl-2.8.15 is unmasked....