aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/php: security fixes for CVE-2014-0237,CVE-2014-0238Natanael Copa2014-06-103-2/+99
| | | | fixes #3021
* main/libvirt: security upgrade to 1.0.5.9 fixes various CVEsNatanael Copa2014-06-105-68/+279
| | | | | | | | | | CVE-2013-6458 CVE-2014-1447 CVE-2013-6456 CVE-2014-0179 fixes #2535 fixes #2953
* main/libtasn1: security fix for CVE-2014-3467, CVE-2014-3468, CVE-2014-3469Natanael Copa2014-06-102-3/+167
| | | | fixes #3010
* main/dovecot: security fix for CVE-2014-3430Natanael Copa2014-06-102-1/+55
| | | | fixes #2957
* main/freeradius: rebuild against new opensslNatanael Copa2014-06-091-1/+1
| | | | ref #3007
* main/openssl: security upgrade to 1.0.1h (multiple CVE)Timo Teräs2014-06-094-130/+4
| | | | | | | | | | | | | | | | | Newly fixed CVEs: CVE-2014-0224 SSL/TLS MITM vulnerability CVE-2014-0221 DTLS recursion flaw CVE-2014-0195 DTLS invalid fragment vulnerability Previously fixed in Alpine by cherry picks: CVE-2014-0198 SSL_MODE_RELEASE_BUFFERS NULL pointer dereference (cherry picked from commit 120a0ce7ae2b324c46ba9e47fb64feaa13913582) Conflicts: main/openssl/APKBUILD fixes #2996
* main/gnutls: security upgrade to 3.1.25 (CVE-2014-3466)Timo Teräs2014-06-041-2/+4
| | | | fixes #2988
* main/openssl: security fix to CVE-2014-0198Timo Teräs2014-05-292-1/+42
| | | | fixes #2917
* main/php: security fix for CVE-2014-0185Natanael Copa2014-05-282-2/+48
| | | | fixes #2937
* main/zabbix: upgrade to 2.0.12Leonardo Arena2014-05-261-4/+4
|
* main/libxml2: security fix for CVE-2014-0191Natanael Copa2014-05-222-2/+40
| | | | fixes #2929
* main/ldns: upgrade to 1.6.17 and security fix for CVE-2014-3209Natanael Copa2014-05-222-3/+86
| | | | fixes #2925
* main/libmms: security upgrade to 0.6.4 (CVE-2014-2892)Natanael Copa2014-05-221-3/+3
| | | | fixes #2908
* main/dpkg: security upgrade to 1.16.14 (CVE-2014-0471)Natanael Copa2014-05-221-2/+2
| | | | fixes #2904
* main/qemu: fix previous commitNatanael Copa2014-05-221-0/+4
|
* main/qemu: security fix for CVE-2014-0150Natanael Copa2014-05-222-5/+19
| | | | fixes #2900
* main/libpng: security upgrade to 1.5.14 (CVE-2013-7353 CVE-2013-7354)Natanael Copa2014-05-221-4/+4
| | | | fixes #2923
* main/mysql: security upgrade to 5.5.37Natanael Copa2014-05-221-4/+4
| | | | | | | | | | | | | | CVE-2014-0001 CVE-2014-0384 CVE-2014-2419 CVE-2014-2430 CVE-2014-2431 CVE-2014-2432 CVE-2014-2436 CVE-2014-2438 CVE-2014-2440 fixes #2913
* main/openssl: fix for CVE-2010-5298Timo Teräs2014-05-212-1/+18
| | | | | | fixes #2896 (cherry picked from commit 4456c9ec91d13627b3900075f8ac84ce97551679)
* main/squid: security fix for CVE-2014-0128Natanael Copa2014-05-142-1/+291
| | | | fixes #2874
* main/libxfont: security fixes for CVE-2014-0209, CVE-2014-0210, CVE-2014-0211Natanael Copa2014-05-1413-5/+954
| | | | fixes #2886
* main/openssh: security fix for CVE-2014-2653Timo Teräs2014-04-212-3/+79
| | | | | | | | fixes #2858 (cherry picked from commit 71bd4159f75887e3fa43dc15fb4f42a81feb0467) Conflicts: main/openssh/APKBUILD
* main/php: security fix for CVE-2013-7345Natanael Copa2014-04-182-14/+67
| | | | fixes #2853
* main/openswan: security upgrade to 2.6.41 (CVE-2013-6466)Timo Teräs2014-04-187-854/+57
| | | | fixes #2829
* main/curl: security upgrade to 7.36.0 (CVE-2014-0138 CVE-2014-0139)Timo Teräs2014-04-182-55/+5
| | | | | | | | | | groff is now needed to build built-in manual. ref #2816 fixes #2818 (cherry picked from commit d218307c3f5ca3bb714075368f71f8c7332371cb) Conflicts: main/curl/APKBUILD
* main/a2ps: security fix for CVE-2001-1593 and CVE-2014-0466Natanael Copa2014-04-183-2/+101
| | | | | | | | fixes #2823 (cherry picked from commit 9544460de3b7282c473654a2a67586c6645a05c1) Conflicts: main/a2ps/APKBUILD
* main/mutt: security upgrade to 1.5.23 (CVE-2014-0467)Timo Teräs2014-04-171-3/+3
| | | | | | | | fixes #2784 (cherry picked from commit bb047f7e617af0cd855a32158cef5f19f3ddf529) Conflicts: main/mutt/APKBUILD
* main/memcached: security upgrade to 1.4.17 ↵Natanael Copa2014-04-171-6/+6
| | | | | | | | | | | (CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291) fixes #2626 (cherry picked from commit 01c5af01dadb92ad64c468444fcd4b58e00ccdc9) Conflicts: main/memcached/APKBUILD
* main/nagios: security fix for CVE-2013-7108, CVE-2013-7205Natanael Copa2014-04-172-3/+208
| | | | fixes #2620
* main/apache2: security upgrade to 2.4.9 (CVE-2013-6438,CVE-2014-0098)Natanael Copa2014-04-171-2/+2
| | | | fixes #2793
* main/postfixadmin: security upgrade to 2.3.7 (CVE-2014-2655)Natanael Copa2014-04-171-2/+2
| | | | fixes #2813
* main/nss: security fix for CVE-2014-1492Timo Teräs2014-04-172-4/+50
| | | | | fixes #2798 (cherry picked from commit 7e5212b7f595cf6e9bee5e565bc6b5bee041efc7)
* main/freeradius: rebuild against new openssl. Fixes #2835Leonardo Arena2014-04-081-1/+1
|
* main/openssl: upgrade to 1.0.1gTimo Teräs2014-04-071-2/+18
| | | | | - fix for CVE-2014-0160 - fix for CVE-2014-0076
* main/squid: upgrade to 3.2.13Natanael Copa2014-03-261-2/+2
| | | | fixes #2775
* main/openssh: security fix for CVE-2014-2532Bartłomiej Piotrowski2014-03-262-2/+34
|
* main/net-snmp: fix buildBartłomiej Piotrowski2014-03-171-1/+0
|
* main/net-snmp: security upgrade to 5.7.2.1 (CVE-2014-2285, CVE-2014-2284)Bartłomiej Piotrowski2014-03-163-43/+70
|
* main/wireshark: security upgrade to 1.8.13 (CVE-2013-7112,CVE-2013-7114)Natanael Copa2014-03-131-2/+2
| | | | fixes #2753
* main/lighttpd: security upgrade to 1.4.35 (CVE-2014-2323,CVE-2014-2324)Natanael Copa2014-03-135-429/+3
| | | | fixes #2765
* main/subversion: security upgrade to 1.7.16 ↵Natanael Copa2014-03-131-2/+2
| | | | | | (CVE-2013-4505,CVE-2013-4558,CVE-2014-0032) fixes #2741
* main/libmodplug: secutity upgrade to 0.8.8.5 (CVE-2013-4233, CVE-2013-4234)Bartłomiej Piotrowski2014-03-131-2/+4
|
* main/jansson: security upgrade to 2.6 (CVE-2013-6401)Bartłomiej Piotrowski2014-03-131-3/+5
|
* main/udisks2: security fix for CVE-2014-0004Bartłomiej Piotrowski2014-03-112-2/+110
|
* main/udisks: security fix for CVE-2014-0004Bartłomiej Piotrowski2014-03-112-2/+93
|
* main/libssh: security fix for CVE-2014-0017Bartłomiej Piotrowski2014-03-102-5/+76
|
* main/phpmyadmin: security fix for CVE-2014-1879Natanael Copa2014-03-072-2/+20
| | | | fixes #2736
* main/postgresql: security upgrade to 9.2.7 (various CVEs)Natanael Copa2014-03-051-2/+2
| | | | | | | | | | | | | | | fixes #2729 CVE-2014-0060 SET ROLE bypasses lack of ADMIN OPTION. CVE-2014-0061 Privilege escalation via calls to validator functions. CVE-2014-0062 Race condition in CREATE INDEX allows for privilege escalation. CVE-2014-0063 Potential buffer overruns due to integer overflow in size calculations. CVE-2014-0064 Potential buffer overruns in datetime input/output. CVE-2014-0065 Potential buffer overruns of fixed-size buffers. CVE-2014-0066 Potential null pointer dereference crash when crypt(3) returns NULL.
* main/php: security fix CVE-2013-6712. Fixes #2650Leonardo Arena2014-03-052-2/+33
|
* main/gnutls: security upgrade to 3.1.22 (CVE-2014-0092,CVE-2014-1959)Natanael Copa2014-03-051-4/+2
| | | | fixes #2725