aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authorbrnrd <brnrd@FreeBSD.org>2016-07-19 04:15:17 +0800
committerbrnrd <brnrd@FreeBSD.org>2016-07-19 04:15:17 +0800
commit4e2ab95915ce03b594222d52c4f76b7c1c17b89a (patch)
treedd546febe1aa454e480c772dc0d749789a343431 /security
parent82a05703b4b4a60fc990c783612994f6e898a045 (diff)
downloadfreebsd-ports-gnome-4e2ab95915ce03b594222d52c4f76b7c1c17b89a.tar.gz
freebsd-ports-gnome-4e2ab95915ce03b594222d52c4f76b7c1c17b89a.tar.zst
freebsd-ports-gnome-4e2ab95915ce03b594222d52c4f76b7c1c17b89a.zip
www/apache24: Fix httpoxy vulnerability (+2.2)
- Mark new Apache revisions not vulnerable - Add apache22-mpm-* ports - Add Apache CVE-number Security: cf0b5668-4d1b-11e6-b2ec-b499baebfeaf Security: CVE-2016-5387
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml10
1 files changed, 8 insertions, 2 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index b12f3deb8605..79aaabf3d978 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -63,11 +63,15 @@ Notes:
<affects>
<package>
<name>apache22</name>
- <range><ge>0</ge></range>
+ <name>apache22-event-mpm</name>
+ <name>apache22-itk-mpm</name>
+ <name>apache22-peruser-mpm</name>
+ <name>apache22-worker-mpm</name>
+ <range><lt>2.2.31_1</lt></range>
</package>
<package>
<name>apache24</name>
- <range><ge>0</ge></range>
+ <range><lt>2.4.23_1</lt></range>
</package>
<package>
<name>tomcat6</name>
@@ -142,12 +146,14 @@ Notes:
<url>https://www.kb.cert.org/vuls/id/797896</url>
<url>CVE-2016-5385</url>
<url>CVE-2016-5386</url>
+ <url>CVE-2016-5387</url>
<url>CVE-2016-5388</url>
<url>CVE-2016-1000110</url>
</references>
<dates>
<discovery>2016-07-18</discovery>
<entry>2016-07-18</entry>
+ <modified>2016-07-18</modified>
</dates>
</vuln>