Re: [users@httpd] HTTPOxy vulnerability not posted to announce list?

2017-01-04 Thread William A Rowe Jr
https://lists.apache.org/list.html?annou...@httpd.apache.org:lte=1y:Httpoxy was the first release addressing the question by httpd project. Announce@ lists are used to broadcast release availability, making them less than ideal channels for this foundation-wide response; https://www.apache.org/s

Re: [users@httpd] Re: Next version of Apache 2.2?

2017-01-04 Thread Rainer Jung
Am 03.01.2017 um 23:19 schrieb Good guy: On 03/01/2017 21:31, Development Manager wrote: CVE-2016-8743 was patched/mitigated in Apache 2.4 but is still an outstanding issue in 2.2, according to https://security-tracker.debian.org/tracker/CVE-2016-8743. Is there a plan to rebase it to 2.2? If so