Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/php: security fixes for CVE-2014-0237,CVE-2014-0238 | Natanael Copa | 2014-06-10 | 3 | -2/+99 | |
| | | | | fixes #3021 | |||||
* | main/libvirt: security upgrade to 1.0.5.9 fixes various CVEs | Natanael Copa | 2014-06-10 | 5 | -68/+279 | |
| | | | | | | | | | | CVE-2013-6458 CVE-2014-1447 CVE-2013-6456 CVE-2014-0179 fixes #2535 fixes #2953 | |||||
* | main/libtasn1: security fix for CVE-2014-3467, CVE-2014-3468, CVE-2014-3469 | Natanael Copa | 2014-06-10 | 2 | -3/+167 | |
| | | | | fixes #3010 | |||||
* | main/dovecot: security fix for CVE-2014-3430 | Natanael Copa | 2014-06-10 | 2 | -1/+55 | |
| | | | | fixes #2957 | |||||
* | main/freeradius: rebuild against new openssl | Natanael Copa | 2014-06-09 | 1 | -1/+1 | |
| | | | | ref #3007 | |||||
* | main/openssl: security upgrade to 1.0.1h (multiple CVE) | Timo Teräs | 2014-06-09 | 4 | -130/+4 | |
| | | | | | | | | | | | | | | | | | Newly fixed CVEs: CVE-2014-0224 SSL/TLS MITM vulnerability CVE-2014-0221 DTLS recursion flaw CVE-2014-0195 DTLS invalid fragment vulnerability Previously fixed in Alpine by cherry picks: CVE-2014-0198 SSL_MODE_RELEASE_BUFFERS NULL pointer dereference (cherry picked from commit 120a0ce7ae2b324c46ba9e47fb64feaa13913582) Conflicts: main/openssl/APKBUILD fixes #2996 | |||||
* | main/gnutls: security upgrade to 3.1.25 (CVE-2014-3466) | Timo Teräs | 2014-06-04 | 1 | -2/+4 | |
| | | | | fixes #2988 | |||||
* | main/openssl: security fix to CVE-2014-0198 | Timo Teräs | 2014-05-29 | 2 | -1/+42 | |
| | | | | fixes #2917 | |||||
* | main/php: security fix for CVE-2014-0185 | Natanael Copa | 2014-05-28 | 2 | -2/+48 | |
| | | | | fixes #2937 | |||||
* | main/zabbix: upgrade to 2.0.12 | Leonardo Arena | 2014-05-26 | 1 | -4/+4 | |
| | ||||||
* | main/libxml2: security fix for CVE-2014-0191 | Natanael Copa | 2014-05-22 | 2 | -2/+40 | |
| | | | | fixes #2929 | |||||
* | main/ldns: upgrade to 1.6.17 and security fix for CVE-2014-3209 | Natanael Copa | 2014-05-22 | 2 | -3/+86 | |
| | | | | fixes #2925 | |||||
* | main/libmms: security upgrade to 0.6.4 (CVE-2014-2892) | Natanael Copa | 2014-05-22 | 1 | -3/+3 | |
| | | | | fixes #2908 | |||||
* | main/dpkg: security upgrade to 1.16.14 (CVE-2014-0471) | Natanael Copa | 2014-05-22 | 1 | -2/+2 | |
| | | | | fixes #2904 | |||||
* | main/qemu: fix previous commit | Natanael Copa | 2014-05-22 | 1 | -0/+4 | |
| | ||||||
* | main/qemu: security fix for CVE-2014-0150 | Natanael Copa | 2014-05-22 | 2 | -5/+19 | |
| | | | | fixes #2900 | |||||
* | main/libpng: security upgrade to 1.5.14 (CVE-2013-7353 CVE-2013-7354) | Natanael Copa | 2014-05-22 | 1 | -4/+4 | |
| | | | | fixes #2923 | |||||
* | main/mysql: security upgrade to 5.5.37 | Natanael Copa | 2014-05-22 | 1 | -4/+4 | |
| | | | | | | | | | | | | | | CVE-2014-0001 CVE-2014-0384 CVE-2014-2419 CVE-2014-2430 CVE-2014-2431 CVE-2014-2432 CVE-2014-2436 CVE-2014-2438 CVE-2014-2440 fixes #2913 | |||||
* | main/openssl: fix for CVE-2010-5298 | Timo Teräs | 2014-05-21 | 2 | -1/+18 | |
| | | | | | | fixes #2896 (cherry picked from commit 4456c9ec91d13627b3900075f8ac84ce97551679) | |||||
* | main/squid: security fix for CVE-2014-0128 | Natanael Copa | 2014-05-14 | 2 | -1/+291 | |
| | | | | fixes #2874 | |||||
* | main/libxfont: security fixes for CVE-2014-0209, CVE-2014-0210, CVE-2014-0211 | Natanael Copa | 2014-05-14 | 13 | -5/+954 | |
| | | | | fixes #2886 | |||||
* | main/openssh: security fix for CVE-2014-2653 | Timo Teräs | 2014-04-21 | 2 | -3/+79 | |
| | | | | | | | | fixes #2858 (cherry picked from commit 71bd4159f75887e3fa43dc15fb4f42a81feb0467) Conflicts: main/openssh/APKBUILD | |||||
* | main/php: security fix for CVE-2013-7345 | Natanael Copa | 2014-04-18 | 2 | -14/+67 | |
| | | | | fixes #2853 | |||||
* | main/openswan: security upgrade to 2.6.41 (CVE-2013-6466) | Timo Teräs | 2014-04-18 | 7 | -854/+57 | |
| | | | | fixes #2829 | |||||
* | main/curl: security upgrade to 7.36.0 (CVE-2014-0138 CVE-2014-0139) | Timo Teräs | 2014-04-18 | 2 | -55/+5 | |
| | | | | | | | | | | groff is now needed to build built-in manual. ref #2816 fixes #2818 (cherry picked from commit d218307c3f5ca3bb714075368f71f8c7332371cb) Conflicts: main/curl/APKBUILD | |||||
* | main/a2ps: security fix for CVE-2001-1593 and CVE-2014-0466 | Natanael Copa | 2014-04-18 | 3 | -2/+101 | |
| | | | | | | | | fixes #2823 (cherry picked from commit 9544460de3b7282c473654a2a67586c6645a05c1) Conflicts: main/a2ps/APKBUILD | |||||
* | main/mutt: security upgrade to 1.5.23 (CVE-2014-0467) | Timo Teräs | 2014-04-17 | 1 | -3/+3 | |
| | | | | | | | | fixes #2784 (cherry picked from commit bb047f7e617af0cd855a32158cef5f19f3ddf529) Conflicts: main/mutt/APKBUILD | |||||
* | main/memcached: security upgrade to 1.4.17 ↵ | Natanael Copa | 2014-04-17 | 1 | -6/+6 | |
| | | | | | | | | | | | (CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291) fixes #2626 (cherry picked from commit 01c5af01dadb92ad64c468444fcd4b58e00ccdc9) Conflicts: main/memcached/APKBUILD | |||||
* | main/nagios: security fix for CVE-2013-7108, CVE-2013-7205 | Natanael Copa | 2014-04-17 | 2 | -3/+208 | |
| | | | | fixes #2620 | |||||
* | main/apache2: security upgrade to 2.4.9 (CVE-2013-6438,CVE-2014-0098) | Natanael Copa | 2014-04-17 | 1 | -2/+2 | |
| | | | | fixes #2793 | |||||
* | main/postfixadmin: security upgrade to 2.3.7 (CVE-2014-2655) | Natanael Copa | 2014-04-17 | 1 | -2/+2 | |
| | | | | fixes #2813 | |||||
* | main/nss: security fix for CVE-2014-1492 | Timo Teräs | 2014-04-17 | 2 | -4/+50 | |
| | | | | | fixes #2798 (cherry picked from commit 7e5212b7f595cf6e9bee5e565bc6b5bee041efc7) | |||||
* | main/freeradius: rebuild against new openssl. Fixes #2835 | Leonardo Arena | 2014-04-08 | 1 | -1/+1 | |
| | ||||||
* | main/openssl: upgrade to 1.0.1g | Timo Teräs | 2014-04-07 | 1 | -2/+18 | |
| | | | | | - fix for CVE-2014-0160 - fix for CVE-2014-0076 | |||||
* | main/squid: upgrade to 3.2.13 | Natanael Copa | 2014-03-26 | 1 | -2/+2 | |
| | | | | fixes #2775 | |||||
* | main/openssh: security fix for CVE-2014-2532 | Bartłomiej Piotrowski | 2014-03-26 | 2 | -2/+34 | |
| | ||||||
* | main/net-snmp: fix build | Bartłomiej Piotrowski | 2014-03-17 | 1 | -1/+0 | |
| | ||||||
* | main/net-snmp: security upgrade to 5.7.2.1 (CVE-2014-2285, CVE-2014-2284) | Bartłomiej Piotrowski | 2014-03-16 | 3 | -43/+70 | |
| | ||||||
* | main/wireshark: security upgrade to 1.8.13 (CVE-2013-7112,CVE-2013-7114) | Natanael Copa | 2014-03-13 | 1 | -2/+2 | |
| | | | | fixes #2753 | |||||
* | main/lighttpd: security upgrade to 1.4.35 (CVE-2014-2323,CVE-2014-2324) | Natanael Copa | 2014-03-13 | 5 | -429/+3 | |
| | | | | fixes #2765 | |||||
* | main/subversion: security upgrade to 1.7.16 ↵ | Natanael Copa | 2014-03-13 | 1 | -2/+2 | |
| | | | | | | (CVE-2013-4505,CVE-2013-4558,CVE-2014-0032) fixes #2741 | |||||
* | main/libmodplug: secutity upgrade to 0.8.8.5 (CVE-2013-4233, CVE-2013-4234) | Bartłomiej Piotrowski | 2014-03-13 | 1 | -2/+4 | |
| | ||||||
* | main/jansson: security upgrade to 2.6 (CVE-2013-6401) | Bartłomiej Piotrowski | 2014-03-13 | 1 | -3/+5 | |
| | ||||||
* | main/udisks2: security fix for CVE-2014-0004 | Bartłomiej Piotrowski | 2014-03-11 | 2 | -2/+110 | |
| | ||||||
* | main/udisks: security fix for CVE-2014-0004 | Bartłomiej Piotrowski | 2014-03-11 | 2 | -2/+93 | |
| | ||||||
* | main/libssh: security fix for CVE-2014-0017 | Bartłomiej Piotrowski | 2014-03-10 | 2 | -5/+76 | |
| | ||||||
* | main/phpmyadmin: security fix for CVE-2014-1879 | Natanael Copa | 2014-03-07 | 2 | -2/+20 | |
| | | | | fixes #2736 | |||||
* | main/postgresql: security upgrade to 9.2.7 (various CVEs) | Natanael Copa | 2014-03-05 | 1 | -2/+2 | |
| | | | | | | | | | | | | | | | fixes #2729 CVE-2014-0060 SET ROLE bypasses lack of ADMIN OPTION. CVE-2014-0061 Privilege escalation via calls to validator functions. CVE-2014-0062 Race condition in CREATE INDEX allows for privilege escalation. CVE-2014-0063 Potential buffer overruns due to integer overflow in size calculations. CVE-2014-0064 Potential buffer overruns in datetime input/output. CVE-2014-0065 Potential buffer overruns of fixed-size buffers. CVE-2014-0066 Potential null pointer dereference crash when crypt(3) returns NULL. | |||||
* | main/php: security fix CVE-2013-6712. Fixes #2650 | Leonardo Arena | 2014-03-05 | 2 | -2/+33 | |
| | ||||||
* | main/gnutls: security upgrade to 3.1.22 (CVE-2014-0092,CVE-2014-1959) | Natanael Copa | 2014-03-05 | 1 | -4/+2 | |
| | | | | fixes #2725 |