Mailing List Archive

RE: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS?
Homebrew seems to add an additional version of httpd rather than upgrading the existing built-in version.

Apache.org does not have a package for MacOS to patch the built-in Mac version of httpd.

The current MacOS that was just released this week is still including an older version of Apache.


RICH BARRON
SR. IT SUPPORT SPECIALIST

M: + 9513168861

Rich.Barron@Revance.com
[/var/folders/87/ln49b9r97j5cpntmwb0hzw7s0yfmj5/T/com.microsoft.Word/WebArchiveCopyPasteTempFiles/cidimage001.png@01D60777.922CA3B0]<https://www.revance.com/> | [A picture containing drawing Description automatically generated] <https://www.instagram.com/revancetherapeutics/> [/var/folders/87/ln49b9r97j5cpntmwb0hzw7s0yfmj5/T/com.microsoft.Word/WebArchiveCopyPasteTempFiles/cidimage003.png@01D60777.922CA3B0] <https://www.facebook.com/realrevancetherapeutics/> [/var/folders/87/ln49b9r97j5cpntmwb0hzw7s0yfmj5/T/com.microsoft.Word/WebArchiveCopyPasteTempFiles/cidimage004.png@01D60777.922CA3B0] <https://www.linkedin.com/company/revance-therapeutics/>
18201 Von Karman
Suite# 120
Irvine, California 92612
Revance.com

24/7 Help Desk: 855-459-8267
helpdesk@revance.com<mailto:helpdesk@revance.com>

"Save Often And Restart Once A Week!"

From: Will Fatherley <wefatherley@gmail.com>
Sent: Wednesday, October 27, 2021 2:49 PM
To: users@httpd.apache.org
Subject: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS?


How can we upgrade to current on the Mac?

You can use a package manager like Homebrew, but make sure you verify the package manager repository has the patched source.

Alternatively, you can obtain the source by visiting https.apache.org<https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fhttps.apache.org%2F&data=04%7C01%7Crich.barron%40revance.com%7C6f04cd38811c412eddda08d99993a36d%7C48a554d384034f70b3609b01ba297b36%7C0%7C1%7C637709681661769902%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=FUCiR%2F%2FG4D0bc8h5izrE77c%2BaIzLOozJindVBGkCx%2BA%3D&reserved=0>, and building it yourself.

There're definitely other avenues to do this also.
Re: RE: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS? [ In reply to ]
It would be better to build from the source @apache.org rather than patching the shipped version on Mac. Definitely it requires some reading and fixing things during compilation. Hope it helps.

Thanks,
Anil
Sent from my iPhone

> On Oct 27, 2021, at 16:52, Rich Barron <rich.barron@revance.com> wrote:
>
> ?
> Homebrew seems to add an additional version of httpd rather than upgrading the existing built-in version.
>
> Apache.org does not have a package for MacOS to patch the built-in Mac version of httpd.
>
> The current MacOS that was just released this week is still including an older version of Apache.
>
>
> RICH BARRON
> SR. IT SUPPORT SPECIALIST
>
> M: + 9513168861
>
> Rich.Barron@Revance.com
>
> |
> 18201 Von Karman
> Suite# 120
> Irvine, California 92612
> Revance.com
>
> 24/7 Help Desk: 855-459-8267
> helpdesk@revance.com
>
> “Save Often And Restart Once A Week!”
>
> From: Will Fatherley <wefatherley@gmail.com>
> Sent: Wednesday, October 27, 2021 2:49 PM
> To: users@httpd.apache.org
> Subject: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS?
>
>
> How can we upgrade to current on the Mac?
>
> You can use a package manager like Homebrew, but make sure you verify the package manager repository has the patched source.
>
> Alternatively, you can obtain the source by visiting https.apache.org, and building it yourself.
>
> There’re definitely other avenues to do this also.
RE: RE: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS? [ In reply to ]
We are doing a security audit. The software saw the unpatched version in the MacOS and flagged it as a violation – so that is what needs to be patched.

We don’t use Apache at all – but it is outdated software and needs to be removed or updated. I don’t see a way to remove it from the Mac, nor do I see a way to update it.

RICH B


From: Anil Kumar P <naeduani@gmail.com>
Sent: Wednesday, October 27, 2021 4:16 PM
To: users@httpd.apache.org
Subject: Re: [users@httpd] RE: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS?

It would be better to build from the source @apache.org rather than patching the shipped version on Mac. Definitely it requires some reading and fixing things during compilation. Hope it helps.

Thanks,
Anil
Sent from my iPhone


On Oct 27, 2021, at 16:52, Rich Barron <rich.barron@revance.com<mailto:rich.barron@revance.com>> wrote:
?
Homebrew seems to add an additional version of httpd rather than upgrading the existing built-in version.

Apache.org does not have a package for MacOS to patch the built-in Mac version of httpd.

The current MacOS that was just released this week is still including an older version of Apache.


RICH BARRON
SR. IT SUPPORT SPECIALIST

M: + 9513168861

Rich.Barron@Revance.com
[/var/folders/87/ln49b9r97j5cpntmwb0hzw7s0yfmj5/T/com.microsoft.Word/WebArchiveCopyPasteTempFiles/cidimage001.png@01D60777.922CA3B0]<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.revance.com%2F&data=04%7C01%7Crich.barron%40revance.com%7C77c5da4909144093830208d9999fb365%7C48a554d384034f70b3609b01ba297b36%7C0%7C1%7C637709733509042283%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=FqAo2mIEipkb8dd71dQQYeQy6Zkog5fpybI6j3SVFUs%3D&reserved=0> | [A picture containing drawing Description automatically generated] <https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.instagram.com%2Frevancetherapeutics%2F&data=04%7C01%7Crich.barron%40revance.com%7C77c5da4909144093830208d9999fb365%7C48a554d384034f70b3609b01ba297b36%7C0%7C1%7C637709733509052238%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=QS9OQ5K1ied62DOlkJStLKHgT5FePseBBD0s4mY6I9U%3D&reserved=0> [/var/folders/87/ln49b9r97j5cpntmwb0hzw7s0yfmj5/T/com.microsoft.Word/WebArchiveCopyPasteTempFiles/cidimage003.png@01D60777.922CA3B0] <https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.facebook.com%2Frealrevancetherapeutics%2F&data=04%7C01%7Crich.barron%40revance.com%7C77c5da4909144093830208d9999fb365%7C48a554d384034f70b3609b01ba297b36%7C0%7C1%7C637709733509052238%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=Zx3t9awtthhuakfrjcHZ97IruF7ziKagPIRnrcCOYK4%3D&reserved=0> [/var/folders/87/ln49b9r97j5cpntmwb0hzw7s0yfmj5/T/com.microsoft.Word/WebArchiveCopyPasteTempFiles/cidimage004.png@01D60777.922CA3B0] <https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Frevance-therapeutics%2F&data=04%7C01%7Crich.barron%40revance.com%7C77c5da4909144093830208d9999fb365%7C48a554d384034f70b3609b01ba297b36%7C0%7C1%7C637709733509062201%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=o8rdnBB5ahEiW0%2BZzU9Vj3%2Fcmy65TiFMC%2FLCGr%2Bu88A%3D&reserved=0>
18201 Von Karman
Suite# 120
Irvine, California 92612
Revance.com

24/7 Help Desk: 855-459-8267
helpdesk@revance.com<mailto:helpdesk@revance.com>


“Save Often And Restart Once A Week!”

From: Will Fatherley <wefatherley@gmail.com<mailto:wefatherley@gmail.com>>
Sent: Wednesday, October 27, 2021 2:49 PM
To: users@httpd.apache.org<mailto:users@httpd.apache.org>
Subject: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS?


How can we upgrade to current on the Mac?

You can use a package manager like Homebrew, but make sure you verify the package manager repository has the patched source.

Alternatively, you can obtain the source by visiting https.apache.org<https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fhttps.apache.org%2F&data=04%7C01%7Crich.barron%40revance.com%7C77c5da4909144093830208d9999fb365%7C48a554d384034f70b3609b01ba297b36%7C0%7C1%7C637709733509062201%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=%2FRseU3wGnPZFjPPXlmxKY3i024DDl%2Bia%2F8LlUl2mahg%3D&reserved=0>, and building it yourself.

There’re definitely other avenues to do this also.
Re: RE: (EXTERNAL) Re: [users@httpd] Patching httpd in MacOS? [ In reply to ]
On Thu, Oct 28, 2021 at 1:18 AM Rich Barron <rich.barron@revance.com> wrote:
>
> We are doing a security audit. The software saw the unpatched version in the MacOS and flagged it as a violation – so that is what needs to be patched.

I don't know how Apple handles bundled software. Are you sure that
this is not a false positive and that the relevant security issues
have not been patched even though the version number wasn't changed?

Anyway, I think this is a MacOS problem, you'll have to find out how
to disable, uninstall or update httpd with the MacOS specific tools,
find evidence that the installed httpd is actually safe or plead with
Apple to provide an update.

rainer

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org