source: trunk/server/fedora/specs/httpd.spec.patch @ 2791

Last change on this file since 2791 was 2774, checked in by andersk, 8 years ago
Apply the 2015 suexec patch for CVE-2016-5387 “httpoxy”. Also remove our inexplicable whitelist entry for HTTPS_* environment variables.
File size: 3.3 KB
RevLine 
[2625]1--- httpd.spec.~1~      2014-07-23 06:24:15.000000000 -0400
2+++ httpd.spec  2014-10-09 03:26:23.922059553 -0400
[2591]3@@ -15,7 +15,7 @@
[926]4 Summary: Apache HTTP Server
5 Name: httpd
[2591]6 Version: 2.4.10
[2673]7-Release: 2%{?dist}
8+Release: 2%{?dist}.scripts.%{scriptsversion}
[926]9 URL: http://httpd.apache.org/
[1738]10 Source0: http://www.apache.org/dist/httpd/httpd-%{version}.tar.bz2
[926]11 Source1: index.html
[2774]12@@ -65,6 +65,16 @@
[2673]13 Patch101: httpd-2.4.6-CVE-2014-3581.patch
14 Patch102: httpd-2.4.10-CVE-2014-3583.patch
15 Patch103: httpd-2.4.10-CVE-2014-8109.patch
[2591]16+
17+Patch1001: httpd-suexec-scripts.patch
18+Patch1002: httpd-mod_status-security.patch
19+Patch1003: httpd-304s.patch
20+Patch1004: httpd-fixup-vhost.patch
21+Patch1005: httpd-allow-null-user.patch
[2602]22+Patch1006: httpd-suexec-journald.patch
[2625]23+Patch1007: httpd-bug57070.patch
[2774]24+Patch1008: httpd-suexec-CVE-2016-5387.patch
[2591]25+
26 License: ASL 2.0
27 Group: System Environment/Daemons
28 BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root
[2625]29@@ -77,6 +86,7 @@
[2591]30 Provides: webserver
31 Provides: mod_dav = %{version}-%{release}, httpd-suexec = %{version}-%{release}
32 Provides: httpd-mmn = %{mmn}, httpd-mmn = %{mmnisa}, httpd-mmn = %{oldmmnisa}
[2066]33+Provides: scripts-httpd = %{version}-%{release}
[2591]34 Requires: httpd-tools = %{version}-%{release}
35 Requires(pre): /usr/sbin/useradd
36 Requires(preun): systemd-units
[2625]37@@ -94,6 +104,7 @@
[1607]38 Obsoletes: secureweb-devel, apache-devel, stronghold-apache-devel
39 Requires: apr-devel, apr-util-devel, pkgconfig
40 Requires: httpd = %{version}-%{release}
[2066]41+Provides: scripts-httpd-devel = %{version}-%{release}
[1607]42 
43 %description devel
44 The httpd-devel package contains the APXS binary and other files
[2625]45@@ -132,6 +143,7 @@
[2066]46 Requires(post): openssl, /bin/cat
[1499]47 Requires(pre): httpd
[2066]48 Requires: httpd = 0:%{version}-%{release}, httpd-mmn = %{mmnisa}
[925]49+Provides: scripts-mod_ssl
50 Obsoletes: stronghold-mod_ssl
51 
52 %description -n mod_ssl
[2774]53@@ -190,6 +202,15 @@
[2591]54 %patch55 -p1 -b .malformedhost
55 %patch56 -p1 -b .uniqueid
[1]56 
[2591]57+%patch1001 -p1 -b .suexec-scripts
58+%patch1002 -p1 -b .mod_status-security
59+%patch1003 -p1 -b .scripts-304s
60+%patch1004 -p1 -b .fixup-vhost
61+%patch1005 -p1 -b .allow-null-user
[2602]62+%patch1006 -p1 -b .journald
[2625]63+%patch1007 -p0 -b .bug57070
[2774]64+%patch1008 -p0 -b .CVE-2016-5387
[1]65+
[2591]66 # Patch in the vendor string
67 sed -i '/^#define PLATFORM/s/Unix/%{vstring}/' os/unix/os.h
68 
[2625]69@@ -242,11 +262,13 @@
[684]70        --enable-suexec --with-suexec \
[2591]71         --enable-suexec-capabilities \
[684]72        --with-suexec-caller=%{suexec_caller} \
[2591]73-       --with-suexec-docroot=%{docroot} \
74-       --without-suexec-logfile \
75-        --with-suexec-syslog \
[1288]76+       --with-suexec-docroot=/ \
[684]77+       --with-suexec-userdir=web_scripts \
[824]78+       --with-suexec-trusteddir=/usr/libexec/scripts-trusted \
[2591]79+       --with-suexec-logfile=%{_localstatedir}/log/httpd/suexec.log \
80+        --without-suexec-syslog \
[684]81        --with-suexec-bin=%{_sbindir}/suexec \
82-       --with-suexec-uidmin=500 --with-suexec-gidmin=100 \
83+       --with-suexec-uidmin=50 --with-suexec-gidmin=50 \
84         --enable-pie \
85         --with-pcre \
[2591]86         --enable-mods-shared=all \
[2625]87@@ -542,7 +564,8 @@
[2591]88 %{_sbindir}/fcgistarter
89 %{_sbindir}/apachectl
90 %{_sbindir}/rotatelogs
91-%caps(cap_setuid,cap_setgid+pe) %attr(510,root,%{suexec_caller}) %{_sbindir}/suexec
92+# cap_dac_override needed to write to /var/log/httpd
[2707]93+%caps(cap_setuid,cap_setgid,cap_dac_override+pe) %attr(555,root,%{suexec_caller}) %{_sbindir}/suexec
[2591]94 
95 %dir %{_libdir}/httpd
96 %dir %{_libdir}/httpd/modules
Note: See TracBrowser for help on using the repository browser.