see subject, will probably not get a new apache release. Patch: http://svn.apache.org/viewvc?view=rev&revision=682870
CVE-2008-2939 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2939): Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via wildcards in a pathname in an FTP URI.
2.2.9-r1 in cvs
Arches, please test and mark stable: =www-servers/apache-2.2.9-r1 Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
amd64/x86 stable
sparc stable
alpha/ia64 stable
ppc stable
ppc64 stable
Stable for HPPA.
it's a vote. I vote NO.
no too, and closing.