HomeFreeBSD

Bring another several patches from Gentoo and Red Hat (also relevant to the

Description

Bring another several patches from Gentoo and Red Hat (also relevant to the
upcoming 2.26):

  • Fix potential buffer overflow in expand_symlinks() function of libhttpd.c
  • Better handling of tempfile and additional input validation in htpasswd(1)
  • Make sure that the logfile is created or reopened as read/write by thttpd (www) user only (modified to allow group read access as well so web admin won't have to su(1) to super-user or "www" to be able to read logs) [1]

Bump port revision to account for these and previous changes.

Gentoo bug: 458896 [1]
Security: CVE-2013-0348 [1]

Details

Provenance
danfeAuthored on
Parents
rP377323: Handle arch-dependent CFLAGS in Makefile.options because it
Branches
Unknown
Tags
Unknown

Event Timeline