don't have time to look closer this evening, full release notes are at https://dlcdn.apache.org/httpd/CHANGES_2.4.69 On 2026/10/01 16:52, Giovanni Bechis wrote: > Hi, > update to Apache httpd follows. > 20 CVE fixed. > CVE details at https://httpd.apache.org/security/vulnerabilities_24.html > ok ? > Cheers > Giovanni > > Index: Makefile > =================================================================== > RCS file: /cvs/ports/www/apache-httpd/Makefile,v > diff -u -p -r1.145 Makefile > --- Makefile 5 Aug 2026 09:16:35 -0000 1.145 > +++ Makefile 1 Oct 2026 14:44:48 -0000 > @@ -1,7 +1,6 @@ > COMMENT= apache HTTP server > > -V= 2.4.68 > -REVISION= 1 > +V= 2.4.69 > DISTNAME= httpd-${V} > PKGNAME= apache-httpd-${V} > > Index: distinfo > =================================================================== > RCS file: /cvs/ports/www/apache-httpd/distinfo,v > diff -u -p -r1.55 distinfo > --- distinfo 9 Jun 2026 22:03:37 -0000 1.55 > +++ distinfo 1 Oct 2026 14:44:48 -0000 > @@ -1,2 +1,2 @@ > -SHA256 (httpd-2.4.68.tar.gz) = 7ZqdRQD7SLso6v+zunHQbM+G1Jj6E6ufeB2gEMxIhJg= > -SIZE (httpd-2.4.68.tar.gz) = 10065436 > +SHA256 (httpd-2.4.69.tar.gz) = xVG5hh4m8Ub1fhsXZeaciaYLPbDsJSzKsNNig0hwFrs= > +SIZE (httpd-2.4.69.tar.gz) = 10822928 > Index: patches/patch-server_mpm_unix_c > =================================================================== > RCS file: /cvs/ports/www/apache-httpd/patches/patch-server_mpm_unix_c,v > diff -u -p -r1.7 patch-server_mpm_unix_c > --- patches/patch-server_mpm_unix_c 5 Aug 2026 09:16:35 -0000 1.7 > +++ patches/patch-server_mpm_unix_c 1 Oct 2026 14:44:48 -0000 > @@ -1,42 +1,7 @@ > Index: server/mpm_unix.c > --- server/mpm_unix.c.orig > +++ server/mpm_unix.c > -@@ -674,6 +674,34 @@ static apr_status_t dummy_connection(ap_pod_t *pod) > - } > - > - rv = apr_socket_connect(sock, lp->bind_addr); > -+#ifdef __OpenBSD__ > -+ /* OpenBSD's connect() returns EINVAL when the target address is the > -+ * wildcard address (INADDR_ANY / IN6ADDR_ANY), > -+ * Retry against the loopback address in that case. */ > -+ if (rv != APR_SUCCESS && APR_STATUS_IS_EINVAL(rv)) { > -+ int is_wildcard = 0; > -+ > -+ if (lp->bind_addr->family == APR_INET) { > -+ is_wildcard = (lp->bind_addr->sa.sin.sin_addr.s_addr == INADDR_ANY); > -+ } > -+#if APR_HAVE_IPV6 > -+ else if (lp->bind_addr->family == APR_INET6) { > -+ is_wildcard = IN6_IS_ADDR_UNSPECIFIED(&lp->bind_addr->sa.sin6.sin6_addr); > -+ } > -+
Thursday, October 01, 2026
Security update: www/apache-httpd
Hi, update to Apache httpd follows. 20 CVE fixed. CVE details at https://httpd.apache.org/security/vulnerabilities_24.html ok ? Cheers Giovanni Index: Makefile =================================================================== RCS file: /cvs/ports/www/apache-httpd/Makefile,v diff -u -p -r1.145 Makefile --- Makefile 5 Aug 2026 09:16:35 -0000 1.145 +++ Makefile 1 Oct 2026 14:44:48 -0000 @@ -1,7 +1,6 @@ COMMENT= apache HTTP server -V= 2.4.68 -REVISION= 1 +V= 2.4.69 DISTNAME= httpd-${V} PKGNAME= apache-httpd-${V} Index: distinfo =================================================================== RCS file: /cvs/ports/www/apache-httpd/distinfo,v diff -u -p -r1.55 distinfo --- distinfo 9 Jun 2026 22:03:37 -0000 1.55 +++ distinfo 1 Oct 2026 14:44:48 -0000 @@ -1,2 +1,2 @@ -SHA256 (httpd-2.4.68.tar.gz) = 7ZqdRQD7SLso6v+zunHQbM+G1Jj6E6ufeB2gEMxIhJg= -SIZE (httpd-2.4.68.tar.gz) = 10065436 +SHA256 (httpd-2.4.69.tar.gz) = xVG5hh4m8Ub1fhsXZeaciaYLPbDsJSzKsNNig0hwFrs= +SIZE (httpd-2.4.69.tar.gz) = 10822928 Index: patches/patch-server_mpm_unix_c =================================================================== RCS file: /cvs/ports/www/apache-httpd/patches/patch-server_mpm_unix_c,v diff -u -p -r1.7 patch-server_mpm_unix_c --- patches/patch-server_mpm_unix_c 5 Aug 2026 09:16:35 -0000 1.7 +++ patches/patch-server_mpm_unix_c 1 Oct 2026 14:44:48 -0000 @@ -1,42 +1,7 @@ Index: server/mpm_unix.c --- server/mpm_unix.c.orig +++ server/mpm_unix.c -@@ -674,6 +674,34 @@ static apr_status_t dummy_connection(ap_pod_t *pod) - } - - rv = apr_socket_connect(sock, lp->bind_addr); -+#ifdef __OpenBSD__ -+ /* OpenBSD's connect() returns EINVAL when the target address is the -+ * wildcard address (INADDR_ANY / IN6ADDR_ANY), -+ * Retry against the loopback address in that case. */ -+ if (rv != APR_SUCCESS && APR_STATUS_IS_EINVAL(rv)) { -+ int is_wildcard = 0; -+ -+ if (lp->bind_addr->family == APR_INET) { -+ is_wildcard = (lp->bind_addr->sa.sin.sin_addr.s_addr == INADDR_ANY); -+ } -+#if APR_HAVE_IPV6 -+ else if (lp->bind_addr->family == APR_INET6) { -+ is_wildcard = IN6_IS_ADDR_UNSPECIFIED(&lp->bind_addr->sa.sin6.sin6_addr); -+ } -+