Actions
Todo #10419
closedUpdate haproxy ports
Start date:
04/03/2020
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
Description
pfSense-pkg-haproxy depends on net/haproxy18 which is currently 1.8.23
pfSense-pkg-haproxy-devel depends on net/haproxy which is currently 2.0.12
The backend packages are currently vulnerable to CVE-2020-11100 which affects HTTP/2. Though the pfSense packages do not include a means to configure HTTP/2, there is still a potential for advanced/manual configurations to be affected.
The master branch of the FreeBSD ports tree already has corrected versions (1.8.25, 2.0.14), but they have not yet been copied back to the quarterly branch.
Updated by Renato Botelho almost 4 years ago
- Status changed from New to Feedback
- % Done changed from 0 to 100
Done. Bumped haproxy and haproxy-devel pfSense packages to 0.60_4 to let users to see a new version
Actions