Skip to content

Commit cf3bd41

Browse files
CBL-Mariner-BotSumynwajslobodzian
authored
[AUTO-CHERRYPICK] Upgrade httpd to 2.4.62 to address CVE-2024-40725 - branch main (#9928)
Co-authored-by: Sumynwa <sumsharma@microsoft.com> Co-authored-by: jslobodzian <joslobo@microsoft.com>
1 parent 8db67c1 commit cf3bd41

3 files changed

Lines changed: 8 additions & 5 deletions

File tree

SPECS/httpd/httpd.signatures.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,11 +5,11 @@
55
"01-ldap.conf": "cbbbdd396fe056e8ab167abd7b2cb5145b42210bfea38452968ff02a03493fc8",
66
"01-session.conf": "51df0ceeb7dae9922817f4af0554f83fe01d6268025ee08260aeed69be3953d1",
77
"10-listen443.conf": "fc7484790ec6328b9082e04083137551a5ae2e8f4d4696d9846b052915b6a0cb",
8-
"httpd-2.4.61.tar.bz2": "ea8ba86fd95bd594d15e46d25ac5bbda82ae0c9122ad93998cc539c133eaceb6",
8+
"httpd-2.4.62.tar.bz2": "674188e7bf44ced82da8db522da946849e22080d73d16c93f7f4df89e25729ec",
99
"httpd-init.service": "2501b44bdb02f583d98cc5296accbf0af36957b93ed5b871358aeb10a0512a7c",
1010
"httpd-ssl-gencerts": "ae96a94eeb0be8731c0bb976e5b878e0e5a196442a001c9e809bed3873f4755d",
1111
"httpd-ssl-pass-dialog": "b9bd4816dda673ad9294a0fbd2904fac9b96eabddb4d72080ae58b498bcd1db9",
1212
"macros.httpd": "6dbf9313a5d085cb705fa5ef393372ec940008f08bf1c9350f8f49d58df75dff",
1313
"ssl.conf": "6690cb873d2312d0ecffcda3822562cd1b1b11ac44b1fcb7bd1b720a9e53c333"
1414
}
15-
}
15+
}

SPECS/httpd/httpd.spec

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
%define _confdir %{_sysconfdir}
33
Summary: The Apache HTTP Server
44
Name: httpd
5-
Version: 2.4.61
5+
Version: 2.4.62
66
Release: 1%{?dist}
77
License: Apache-2.0
88
Vendor: Microsoft Corporation
@@ -345,6 +345,9 @@ fi
345345
%{_libexecdir}/httpd-ssl-pass-dialog
346346

347347
%changelog
348+
* Thu Jul 25 2024 Sumedh Sharma <sumsharma@microsoft.com> - 2.4.62-1
349+
- Upgrade to 2.4.62 to fix CVE-2024-40725
350+
348351
* Thu Jul 11 2024 Tobias Brick <tobiasb@microsoft.com> - 2.4.61-1
349352
- Upgrade to 2.4.61 to address CVE-2024-38473
350353

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5390,8 +5390,8 @@
53905390
"type": "other",
53915391
"other": {
53925392
"name": "httpd",
5393-
"version": "2.4.61",
5394-
"downloadUrl": "https://archive.apache.org/dist/httpd/httpd-2.4.61.tar.bz2"
5393+
"version": "2.4.62",
5394+
"downloadUrl": "https://archive.apache.org/dist/httpd/httpd-2.4.62.tar.bz2"
53955395
}
53965396
}
53975397
},

0 commit comments

Comments
 (0)