<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.freebsd.org/bugzilla/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.freebsd.org/bugzilla/"
          
          maintainer="bugmeister@FreeBSD.org"
>

    <bug>
          <bug_id>232278</bug_id>
          
          <creation_ts>2018-10-15 12:03:38 +0000</creation_ts>
          <short_desc>www/lighttpd: update to 1.4.51</short_desc>
          <delta_ts>2018-11-09 19:33:21 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Ports &amp; Packages</product>
          <component>Individual Port(s)</component>
          <version>Latest</version>
          <rep_platform>Any</rep_platform>
          <op_sys>Any</op_sys>
          <bug_status>Closed</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>---</priority>
          <bug_severity>Affects Only Me</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Piotr Kubaj">pkubaj</reporter>
          <assigned_to name="Steve Wills">swills</assigned_to>
          <cc>dinoex</cc>
    
    <cc>lantw44</cc>
          

      

      

      <flag name="maintainer-feedback"
          id="33147"
          type_id="3"
          status="+"
          setter="pkubaj"
    />
    <flag name="merge-quarterly"
          id="33148"
          type_id="7"
          status="?"
          setter="pkubaj"
    />

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1016189</commentid>
    <comment_count>0</comment_count>
      <attachid>198170</attachid>
    <who name="Piotr Kubaj">pkubaj</who>
    <bug_when>2018-10-15 12:03:38 +0000</bug_when>
    <thetext>Created attachment 198170
patch

Update port to newly released 1.4.51.

Tested on 11-STABLE.

NOTE: this release fixes some *security* bugs, so MHF is recommended.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1016879</commentid>
    <comment_count>1</comment_count>
    <who name="Steve Wills">swills</who>
    <bug_when>2018-10-19 00:37:06 +0000</bug_when>
    <thetext>Can you please point to the security issue(s)? Would be good to have a VuXML too, but I can do it if you want.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1016924</commentid>
    <comment_count>2</comment_count>
    <who name="Piotr Kubaj">pkubaj</who>
    <bug_when>2018-10-19 08:24:50 +0000</bug_when>
    <thetext>(In reply to Steve Wills from comment #1)
I don&apos;t know myself what security fixes are in this release.

The only info I have is that there are some. That&apos;s why I didn&apos;t send VuXML.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1016945</commentid>
    <comment_count>3</comment_count>
    <who name="Steve Wills">swills</who>
    <bug_when>2018-10-19 12:03:34 +0000</bug_when>
    <thetext>(In reply to Piotr Kubaj from comment #2)
I managed to find these:

https://www.lighttpd.net/2018/10/14/1.4.51/

https://redmine.lighttpd.net/projects/lighttpd/repository/revisions/df8e4f95614e476276a55e34da2aa8b00b1148e9/diff/src/request.c

https://redmine.lighttpd.net/projects/lighttpd/repository/revisions/7e20dc6a4241fd01487d7abaf1492c1d2581c7cb/diff/src/mod_userdir.c

but there&apos;s no CVE or other announcement. We could create a VuXML entry anyway based on these, but I&apos;m not sure what we&apos;d say except what&apos;s in those links.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1016950</commentid>
    <comment_count>4</comment_count>
    <who name="Piotr Kubaj">pkubaj</who>
    <bug_when>2018-10-19 12:28:45 +0000</bug_when>
    <thetext>(In reply to Steve Wills from comment #3)
FreeBSD has getpwnam(), so the 2nd patch doesn&apos;t matter for FreeBSD.

But IMO use-after-free fixes are enough for MFC (and we can put that to VuXML entry).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1020923</commentid>
    <comment_count>5</comment_count>
    <who name="">commit-hook</who>
    <bug_when>2018-11-09 10:55:47 +0000</bug_when>
    <thetext>A commit references this bug:

Author: dinoex
Date: Fri Nov  9 10:54:54 UTC 2018
New revision: 484509
URL: https://svnweb.freebsd.org/changeset/ports/484509

Log:
  - lighttpd - use-after-free vulnerabilities
  PR:		232278

Changes:
  head/security/vuxml/vuln.xml</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1021018</commentid>
    <comment_count>6</comment_count>
    <who name="">commit-hook</who>
    <bug_when>2018-11-09 19:32:01 +0000</bug_when>
    <thetext>A commit references this bug:

Author: swills
Date: Fri Nov  9 19:30:59 UTC 2018
New revision: 484541
URL: https://svnweb.freebsd.org/changeset/ports/484541

Log:
  www/lighttpd: update to 1.4.51

  PR:		232278
  Submitted by:	Piotr Kubaj &lt;pkubaj@anongoth.pl&gt; (maintainer)
  MFH:		2018Q4
  Security:	92a6efd0-e40d-11e8-ada4-408d5cf35399

Changes:
  head/www/lighttpd/Makefile
  head/www/lighttpd/distinfo</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1021019</commentid>
    <comment_count>7</comment_count>
    <who name="">commit-hook</who>
    <bug_when>2018-11-09 19:33:05 +0000</bug_when>
    <thetext>A commit references this bug:

Author: swills
Date: Fri Nov  9 19:32:10 UTC 2018
New revision: 484542
URL: https://svnweb.freebsd.org/changeset/ports/484542

Log:
  MFH: r484541

  www/lighttpd: update to 1.4.51

  PR:		232278
  Submitted by:	Piotr Kubaj &lt;pkubaj@anongoth.pl&gt; (maintainer)
  Security:	92a6efd0-e40d-11e8-ada4-408d5cf35399
  Approved by:	ports-secteam (implicit)

Changes:
_U  branches/2018Q4/
  branches/2018Q4/www/lighttpd/Makefile
  branches/2018Q4/www/lighttpd/distinfo</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1021020</commentid>
    <comment_count>8</comment_count>
    <who name="Steve Wills">swills</who>
    <bug_when>2018-11-09 19:33:21 +0000</bug_when>
    <thetext>Committed, thanks!</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>198170</attachid>
            <date>2018-10-15 12:03:38 +0000</date>
            <delta_ts>2018-10-15 12:04:03 +0000</delta_ts>
            <desc>patch</desc>
            <filename>lighttpd.patch</filename>
            <type>text/plain</type>
            <size>1002</size>
            <attacher name="Piotr Kubaj">pkubaj</attacher>
            
              <data encoding="base64">SW5kZXg6IE1ha2VmaWxlCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIE1ha2VmaWxlCShyZXZpc2lvbiA0ODIxNTIp
CisrKyBNYWtlZmlsZQkod29ya2luZyBjb3B5KQpAQCAtMiw3ICsyLDcgQEAKICMgJEZyZWVCU0Qk
CiAKIFBPUlROQU1FPz0JbGlnaHR0cGQKLVBPUlRWRVJTSU9OPQkxLjQuNTAKK1BPUlRWRVJTSU9O
PQkxLjQuNTEKIENBVEVHT1JJRVM/PQl3d3cKIE1BU1RFUl9TSVRFUz89CWh0dHA6Ly9kb3dubG9h
ZC5saWdodHRwZC5uZXQvbGlnaHR0cGQvcmVsZWFzZXMtMS40LngvCiAKSW5kZXg6IGRpc3RpbmZv
Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT0KLS0tIGRpc3RpbmZvCShyZXZpc2lvbiA0ODIxNTIpCisrKyBkaXN0aW5mbwko
d29ya2luZyBjb3B5KQpAQCAtMSw1ICsxLDUgQEAKLVRJTUVTVEFNUCA9IDE1MzQxODk0MzYKLVNI
QTI1NiAobGlnaHR0cGQtMS40LjUwLnRhci54eikgPSAyOTM3ODMxMmQ4ODg3Y2JjMTRmZmU4YTdm
YWRlZjJkNWEwOGM3ZTdlMWJlOTQyNzk1MTQyMzQ2YWQ5NTYyOWViCi1TSVpFIChsaWdodHRwZC0x
LjQuNTAudGFyLnh6KSA9IDcxODQ4MAorVElNRVNUQU1QID0gMTUzOTYwNDE4NAorU0hBMjU2IChs
aWdodHRwZC0xLjQuNTEudGFyLnh6KSA9IDJhZjlmZGIyNjVkMWYwMjViZmE2MzRlMTM3NzAyMzk3
MTJlY2JkNTg1ZTQ5NzViODIyNmVkZjFkZjc0ZTljODIKK1NJWkUgKGxpZ2h0dHBkLTEuNC41MS50
YXIueHopID0gNzIzMjY4CiBTSEEyNTYgKGxpZ2h0dHBkLTEuNC4yNl9tb2RfaDI2NF9zdHJlYW1p
bmctMi4yLjkucGF0Y2gpID0gZGM5YmQ2ZTI2NzU1Y2MyZTNjY2Y2ZWFmOGNjODllNWQ2OTdmNWE4
NzZmNzEzMThiZTY3YjI4MjI1MzY4ZmQ0ZQogU0laRSAobGlnaHR0cGQtMS40LjI2X21vZF9oMjY0
X3N0cmVhbWluZy0yLjIuOS5wYXRjaCkgPSAyNDIwMzcK
</data>
<flag name="maintainer-approval"
          id="33149"
          type_id="1"
          status="+"
          setter="pkubaj"
    />
          </attachment>
      

    </bug>

</bugzilla>