Project

General

Profile

Todo #10419

Update haproxy ports

Added by Jim Pingle 4 months ago. Updated about 1 month ago.

Status:
Closed
Priority:
High
Category:
haproxy
Target version:
-
Start date:
04/03/2020
Due date:
% Done:

100%

Estimated time:

Description

pfSense-pkg-haproxy depends on net/haproxy18 which is currently 1.8.23
pfSense-pkg-haproxy-devel depends on net/haproxy which is currently 2.0.12

The backend packages are currently vulnerable to CVE-2020-11100 which affects HTTP/2. Though the pfSense packages do not include a means to configure HTTP/2, there is still a potential for advanced/manual configurations to be affected.

The master branch of the FreeBSD ports tree already has corrected versions (1.8.25, 2.0.14), but they have not yet been copied back to the quarterly branch.

History

#1 Updated by Renato Botelho 4 months ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

Done. Bumped haproxy and haproxy-devel pfSense packages to 0.60_4 to let users to see a new version

#2 Updated by DRago_Angel [InV@DER] about 1 month ago

All works fine on 2.0.14

#3 Updated by Jim Pingle about 1 month ago

  • Status changed from Feedback to Closed

Also available in: Atom PDF