web server: macports vs. mac osx server

robert delius royar apple at frinabulax.org
Sun Apr 29 07:58:11 PDT 2007


Sun, 29 Apr 2007 (04:26 -0500 UTC) Ryan Schmidt wrote:

> The mod_perl port exists for the MacPorts version of Apache 1.

% port info mod_perl
mod_perl 1.29, Revision 2, www/mod_perl (Variants: universal, darwin_6)
http://perl.apache.org/

{Embeds a Perl interpreter in the Apache 1.3 server}

Library Dependencies: perl5.8, apache
Platforms: darwin freebsd
Maintainers: bchesneau at mac.com

Note that mod_perl 1.29 is susceptable to a moderately critical DoS 
attack as is mod_perl 2.0.2.  See
http://search.cpan.org/~gozer/mod_perl-1.30/Changes
SECURITY: CVE-2007-1349 (cve.mitre.org) fix unescaped variable 
interpolation in Apache::PerlRun regular expression to prevent regex 
engine tampering. reported by Alex Solovey [Randal L. Schwartz 
<merlyn at stonehenge.com>, Fred Moyer <fred at redhotpenguin.com>]

Both have been upgraded to versions greater than are found in macports. 
The upgrade from MP 1.29 to 1.30 is trivial--requiring a checksum change 
and the version change.

For example on my iMacs I have
% port installed mod_perl
The following ports are currently installed:
   mod_perl @1.30_2

I decided to manage apache2 on my own.

-- 
Dr. Robert Delius Royar                   Associate Professor of English
Morehead State University                             Morehead, Kentucky




More information about the macports-users mailing list