New Ticket     Tickets     Wiki     Browse Source     Timeline     Roadmap     Ticket Reports     Search

Ticket #14140 (closed update: fixed)

Opened 5 years ago

Last modified 4 years ago

UPDATE: apache 1.3.37 to 1.3.41

Reported by: ebgssth@… Owned by: macports-tickets@…
Priority: Normal Milestone:
Component: ports Version: 1.6.0
Keywords: apache Cc:
Port:

Description

MacPorts provides the latest apache2, but apache1 is a bit dated (1.3.37) Unfortunately, 1.3.37 has a minor security flaw.

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

http://secunia.com/cve_reference/CVE-2007-6388/

Please upgrade apache to the latest 1.3.41

Change History

comment:1 Changed 5 years ago by raimue@…

  • Status changed from new to closed
  • Resolution set to fixed

Updated in r33649.

comment:2 Changed 4 years ago by jmr@…

  • Type changed from defect to update

comment:3 Changed 4 years ago by anonymous

  • Milestone Port Updates deleted

Milestone Port Updates deleted

Note: See TracTickets for help on using tickets.