aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/sqlite: security upgrade to 3.8.10.2Natanael Copa2015-08-071-5/+5
| | | | | | | | | CVE-2015-3414 use of uninitialized memory when parsing collation sequences in src/where.c CVE-2015-3415 invalid free() in src/vdbe.c CVE-2015-3416 stack buffer overflow in src/printf.c fixes #4306
* main/wireshark: security upgrade to 1.10.14 (CVE-2015-3182)Natanael Copa2015-08-071-6/+6
| | | | fixes #4302
* main/polkit: various security fixesNatanael Copa2015-08-064-1/+1203
| | | | | | | | | | | | | | CVE-2015-3218 CVE-2015-3255 CVE-2015-4625 ref #4411 fixes #4412 (cherry picked from commit a215f1937c91916b1b5162e49e996708eb456e67) Conflicts: main/polkit/APKBUILD
* main/chrony: security upgrade to 1.31.1Natanael Copa2015-08-061-4/+4
| | | | | | | | CVE-2015-1853: DoS attack on authenticated symmetric NTP associations CVE-2015-1821: Heap-based buffer overflow in access configuration CVE-2015-1822: Use of uninitialized pointer in command processing fixes #4165
* main/chrony: upgrade to 1.30Natanael Copa2015-08-063-35/+22
| | | | | | | (cherry picked from commit 62a9ea4aaff7f6fdf87a1230f20cc022101f77aa) Conflicts: main/chrony/APKBUILD
* main/squashfs-tools: security fix for CVE-2015-4645/4646Natanael Copa2015-08-052-4/+34
| | | | | | | | | | ref #4416 fixes #4417 (cherry picked from commit 10422f18285619f8f57b8b4ab5ca829eb21c115f) Conflicts: main/squashfs-tools/APKBUILD
* main/squashfs-tools: fix variable length array overflowNatanael Copa2015-08-052-6/+32
| | | | | | | | | | | | we can not guarantee that block size specified in user data will not overflow the stack so we need to use malloc. this fixes segfault when doing unsquashfs (cherry picked from commit 2fafe3d1eb933216776b191c85565ec5289161da) Conflicts: main/squashfs-tools/APKBUILD
* main/python: security upgrade to 2.7.10 (CVE-2014-9365)Natanael Copa2015-08-051-4/+4
| | | | fixes #3794
* main/qemu: security fix for CVE-2015-4037Natanael Copa2015-08-052-1/+55
| | | | | ref #4324 fixes #4325
* main/net-snmp: security fix for CVE-2015-5621Natanael Copa2015-08-052-1/+138
| | | | fixes #4499
* main/ghostscript: security fix for CVE-2015-3228Natanael Copa2015-08-042-5/+39
| | | | fixes #4469
* main/bind: security upgrade to 9.9.7_p2 (CVE-2015-4620,CVE-2015-5477)Natanael Copa2015-08-041-4/+4
| | | | fixes #4506
* main/cacti: security upgrade to 0.8.8f (CVE-2015-4634)Natanael Copa2015-07-311-4/+4
| | | | fixes #4479
* main/openssh: security fix for CVE-2015-5600Natanael Copa2015-07-302-4/+55
| | | | fixes #4474
* main/php: security upgrade to 5.5.27 (CVE-2015-3152,CVE-2015-5589,CVE-2015-5590)Natanael Copa2015-07-301-4/+4
| | | | fixes #4487
* main/owncloud: upgrade to 5.0.19Leonardo Arena2015-07-301-4/+4
|
* main/opennhrp: cherry-pick upstream fixesTimo Teräs2015-07-248-26/+169
| | | | (cherry picked from commit 0df48acd155da7f5a1a6ed28ffa0c3d3624084a5)
* main/alpine-conf: fix setup-bootable to handle newer kernel namesNatanael Copa2015-07-162-4/+177
|
* main/openssl: security upgrade to 1.0.1p (CVE-2015-1793)Natanael Copa2015-07-093-156/+24
|
* main/unbound: backport to 1.5.3Francesco Colista2015-06-241-5/+5
|
* main/quagga: fix bgpd patch, and disable handling of coredump signalsTimo Teräs2015-06-233-15/+39
|
* main/quagga: rework the bgp route selection fixTimo Teräs2015-06-233-42/+21
|
* main/cups: security fix for CVE-2015-1158,CVE-2015-1159Natanael Copa2015-06-152-4/+505
| | | | | | | * Improper Update of Reference Count -- CVE-2015-1158 * Cross-Site Scripting -- CVE-2015-1159 fixes #4355
* main/cacti: security upgrade to 0.8.8d (CVE-2015-4342)Natanael Copa2015-06-154-337/+5
| | | | fixes #4360
* main/bind: security upgrade to 9.9.6_p2 (CVE-2015-1349)Natanael Copa2015-06-151-4/+4
| | | | fixes #4364
* main/hostapd: various security fixesNatanael Copa2015-06-159-2/+441
| | | | | | | | | | | | CVE-2015-4141 CVE-2015-4142 CVE-2015-4143 CVE-2015-4144 CVE-2015-4145 CVE-2015-4146 fixes #4338 fixes #4267
* main/wpa_supplicant: various security fixesNatanael Copa2015-06-158-1/+392
| | | | | | | | | | | | CVE-2015-4141 CVE-2015-4142 CVE-2015-4143 CVE-2015-4144 CVE-2015-4145 CVE-2015-4146 fixes #4343 fixes #4267
* main/hostapd: security upgrade to 2.3 (CVE-2014-3686)Natanael Copa2015-06-151-2/+10
| | | | fixes #3521
* main/wpa_supplicant: security upgrade to 2.3 (CVE-2014-3686)Natanael Copa2015-06-151-5/+5
| | | | fixes #3521
* main/php: security upgrade to 5.5.26 (various CVEs)Natanael Copa2015-06-151-4/+4
| | | | | | | | | | | | | | | | CVE-2015-4021 CVE-2015-4022 CVE-2015-4024 CVE-2015-4025 CVE-2015-4026 CVE-2015-2325 CVE-2015-2326 CVE-2015-3414 CVE-2015-3415 CVE-2015-3416 fixes #4311
* main/openssl: upgrade to 1.0.0nTimo Teräs2015-06-123-33/+134
| | | | | | | | | | | | | CVE-2015-1788 Malformed ECParameters causes infinite loop CVE-2015-1789 Exploitable out-of-bounds read in X509_cmp_time CVE-2015-1790 PKCS7 crash with missing EnvelopedContent CVE-2015-1792 CMS verify infinite loop with unknown hash function CVE-2015-1791 Race condition handling NewSessionTicket (cherry picked from commit 0c0f46aad82893010ebb45cd4e710b3ba9fc9af8) Conflicts: main/openssl/APKBUILD
* main/libtasn1: security fix for CVE-2015-3622Natanael Copa2015-06-111-4/+8
| | | | fixes #4233
* main/libtasn1: security fix for CVE-2015-2806Natanael Copa2015-06-113-7/+115
| | | | fixes #4160
* main/squark: remove -dbgTimo Teräs2015-06-031-1/+1
| | | | it's not supported on 2.7
* main/squark: upgrade to 0.6.1Timo Teräs2015-06-031-14/+6
|
* main/mini_httpd: upgrade to 1.21Leonardo Arena2015-06-021-3/+11
| | | | | | Fixes #4262 (cherry picked from commit bdc65e149a4e99828d13892a714517aa8a8679f8)
* main/clamav: security upgrade to 0.98.7 (CVE-2015-2170,CVE-2015-2221)Natanael Copa2015-05-291-4/+4
| | | | fixes #4238
* main/icu: security fix for CVE-2014-8146 and CVE-2014-8147Natanael Copa2015-05-283-4/+35
| | | | fixes #4243
* main/postgresql: security upgrade to 9.3.7 ↵Natanael Copa2015-05-271-5/+5
| | | | | | (CVE-2015-3165,CVE-2015-3166,CVE-2015-3167) fixes #4251
* main/acf-jquery: upgrade to 0.3.1Ted Trask2015-05-221-4/+4
| | | | (cherry picked from commit efbf922806dd889beb4cc8f9cd75b862ec3141f7)
* main/icecast: securit fix for CVE-2015-3026Natanael Copa2015-05-212-2/+34
| | | | fixes #4192
* main/qemu: security fix for CVE-2014-8106Natanael Copa2015-05-213-1/+159
| | | | fixes #3776
* main/qemu: security fix for CVE-2014-3615Natanael Copa2015-05-214-1/+406
| | | | | patches from fedora f20 fixes #3381
* main/qemu: security fix for CVE-2015-3456Natanael Copa2015-05-212-1/+90
| | | | | ref #4181 fixes #4184
* main/ppp: security fix for CVE-2015-3310Natanael Copa2015-05-192-2/+48
| | | | fixes #4197
* main/wpa_supplicant: security fix for CVE-2015-1863Natanael Copa2015-05-192-1/+48
| | | | fixes #4210
* main/mysql: upgrade to 5.5.43Bartłomiej Piotrowski2015-05-091-8/+4
|
* main/gnupg: security upgrade to 2.0.27 (CVE-2015-1606,CVE-2015-1607)Natanael Copa2015-05-051-4/+4
| | | | fixes #4094
* main/cabextract: security upgrade to 1.6 (CVE-2015-2060)Natanael Copa2015-05-051-5/+5
| | | | fixes #4100
* main/libarchive: fix directory traversal in bsdcpio (CVE-2015-2304)Natanael Copa2015-05-052-5/+153
| | | | | | | ref #4104 fixes #4106 (cherry picked from commit 8fcb0a179888b5ce69a7ba1939f77397a7453782)