aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/libpng: security upgrade to 1.6.19 (CVE-2015-8126)Natanael Copa2015-11-301-7/+7
| | | | fixes #4885
* main/dovecot: security upgrade to 2.2.19Natanael Copa2015-11-301-5/+4
| | | | fixes #4895
* main/py-django: security fix CVE-2015-8213Christian Kampka2015-11-302-6/+83
| | | | | | Fixed a settings leak possibility in the date template filter. fixes #4902
* main/sudo: security upgrade to 1.8.15 (CVE-2015-5602)Natanael Copa2015-11-203-19/+19
| | | | fixes #4860
* main/zabbix: upgrade to 2.2.11Leonardo Arena2015-11-131-4/+4
|
* main/xen: security upgrade to 4.3.4Leonardo Arena2015-11-102-43/+10
|
* main/php: security upgrade to 5.5.30Kaarle Ritvanen2015-10-171-4/+4
| | | | | CVE-2015-7803 CVE-2015-7804
* main/subversion: security upgrade to 1.8.14 (CVE-2015-3184,CVE-2015-3187)Natanael Copa2015-10-151-5/+5
| | | | | ref #4728 fixes #4731
* main/apache2: security upgrade to 2.4.16 (CVE-2015-3183,CVE-2015-3185)Natanael Copa2015-10-151-5/+6
| | | | | ref #4722 fixes #4725
* main/spice: security upgrade to 0.12.6Natanael Copa2015-10-132-27/+7
| | | | | | | | | | | | CVE-2015-3247 CVE-2015-5260 CVE-2015-5261 ref #4670 fixes #4674 ref #4762 fixes #4766
* main/py-six: moved from testing and upgrade to 1.9.0Natanael Copa2015-10-131-4/+4
| | | | needed by spice security update
* main/spice-protocol: upgrade to 0.12.10Natanael Copa2015-10-131-4/+4
|
* main/icu: security fix for CVE-2015-1270Natanael Copa2015-10-122-4/+26
| | | | | ref #4677 fixes #4681
* main/freeradius3: upgrade to 3.0.10Leonardo Arena2015-10-125-125/+33
|
* main/qemu: various security fixesNatanael Copa2015-10-0612-1/+923
| | | | | | | | | | | CVE-2015-5165 CVE-2015-5225 CVE-2015-5278 CVE-2015-5279 CVE-2015-6815 fixes #4590 fixes #4662
* main/lxc: fix regression in CVE-2015-1335 patchEivind Uggedal2015-10-052-4/+70
|
* main/acf-weblog: upgrade to 0.10.4Ted Trask2015-10-041-4/+4
| | | | (cherry picked from commit c60b0b0e89591b11da303d4b94e28034af98f6fc)
* main/acf-core: upgrade to 0.18.10Ted Trask2015-10-041-4/+4
| | | | (cherry picked from commit c74beb984e7a3a59ce0bd6f7af4c7938f4d1df36)
* main/screen: security fix for CVE-2015-6806Eivind Uggedal2015-09-302-5/+61
|
* main/rpcbind: security fix for CVE-2015-7236Eivind Uggedal2015-09-302-5/+87
|
* main/lxc: security fix for CVE-2014-1334,CVE-2015-1331,CVE-2015-1335Eivind Uggedal2015-09-304-4/+775
|
* main/conntrack-tools: security upgrade to 1.4.3 (CVE-2015-6496)Natanael Copa2015-09-282-60/+5
| | | | | ref #4564 fixes #4566
* main/acf-alpine-baselayout: upgrade to 0.12.2Ted Trask2015-09-211-4/+4
| | | | (cherry picked from commit 8adbf6628e180e8e20fbe9a91bfcb2b9d86ebbe4)
* main/jasper: security fix for CVE-2015-5203Natanael Copa2015-09-212-4/+206
| | | | | ref #4557 fixes #4559
* main/jasper: security fixes (various)Natanael Copa2015-09-215-1/+429
| | | | | | | | | | CVE-2014-8137.patch CVE-2014-8138.patch CVE-2014-8157.patch CVE-2014-8158.patch ref #3814 fixes #3817
* main/jasper: security fix for CVE-2014-9029Natanael Copa2015-09-212-2/+47
| | | | | ref #3779 fixes #3782
* main/gdk-pixbuf: security upgrade to 2.31.5 (CVE-2015-4491)Natanael Copa2015-09-211-4/+4
| | | | | ref #4527 fixes #4529
* main/roundcubemail: upgrade to 1.0.7Leonardo Arena2015-09-181-4/+4
|
* Merge branch '3.0-stable' of ssh://git.alpinelinux.org/aports into 3.0-stableLeonardo Arena2015-09-183-8/+362
|\
| * main/abuild: fix fetching to a shared nfs direcotryNatanael Copa2015-09-172-4/+358
| |
| * main/gnutls: security upgrade to 3.3.18 (CVE-2015-6251)Natanael Copa2015-09-171-4/+4
| | | | | | | | fixes #4571
* | main/openldap: fix ber_get_next denial of service (CVE-2015-6908)Leonardo Arena2015-09-142-1/+31
|/ | | | | http://www.openldap.org/its/index.cgi/Software%20Bugs?id=8240 (cherry picked from commit 4041a223b7e7b9a7ab163406bc7f4b04a4a8fad3)
* main/bind: security upgrade to 9.10.2_p4 (CVE-2015-5722,CVE-2015-5986)Natanael Copa2015-09-091-4/+4
| | | | fixes #4608
* main/php: security upgrade to 5.5.29Natanael Copa2015-09-091-4/+4
| | | | | | CVE-2015-6834, CVE-2015-6835, CVE-2015-6836, CVE-2015-6837, CVE-2015-6838 fixes #4624
* main/openssh: security fixes from upstreamNatanael Copa2015-08-264-1/+155
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixes #4580 CVE-2015-6563: sshd(8): Portable OpenSSH only: Fixed a privilege separation weakness related to PAM support. Attackers who could successfully compromise the pre-authentication process for remote code execution and who had valid credentials on the host could impersonate other users. Reported by Moritz Jodeit. CVE-2015-6564: sshd(8): Portable OpenSSH only: Fixed a use-after-free bug related to PAM support that was reachable by attackers who could compromise the pre-authentication process for remote code execution. Also reported by Moritz Jodeit. CVE-2015-6565: sshd(8): OpenSSH 6.8 and 6.9 incorrectly set TTYs to be world- writable. Local attackers may be able to write arbitrary messages to logged-in users, including terminal escape sequences. Reported by Nikolay Edigaryev. (cherry picked from commit 26c30cf5be4151eee04678ad118d056de0601833) Conflicts: main/openssh/APKBUILD Conflicts: main/openssh/APKBUILD
* main/zabbix: upgrade to 2.2.10Leonardo Arena2015-08-101-5/+5
|
* main/sqlite: fix source urlNatanael Copa2015-08-071-1/+1
|
* main/pcre: various security fixesNatanael Copa2015-08-074-6/+158
| | | | | | | | | | | | | | CVE-2015-3210 CVE-2015-3217 CVE-2015-5073 fixes #4289 fixes #4402 (cherry picked from commit 77345a923c72d9e8d0a4202d893239ba43b903a3) Conflicts: main/pcre/APKBUILD
* main/pcre: security fix for CVE-2014-8964Natanael Copa2015-08-072-5/+78
| | | | | ref #3731 fixes #3734
* main/sqlite: security upgrade to 3.8.10.2Natanael Copa2015-08-071-5/+5
| | | | | | | | | CVE-2015-3414 use of uninitialized memory when parsing collation sequences in src/where.c CVE-2015-3415 invalid free() in src/vdbe.c CVE-2015-3416 stack buffer overflow in src/printf.c fixes #4305
* main/wireshark: security upgrade to 1.10.14 (CVE-2015-3182)Natanael Copa2015-08-071-6/+6
| | | | fixes #4301
* main/polkit: various security fixesNatanael Copa2015-08-064-1/+1203
| | | | | | | | | | | CVE-2015-3218 CVE-2015-3255 CVE-2015-4625 ref #4411 fixes #4413 (cherry picked from commit a215f1937c91916b1b5162e49e996708eb456e67)
* main/squashfs-tools: security fix for CVE-2015-4645/4646Natanael Copa2015-08-052-4/+34
| | | | | | | | | | ref #4416 fixes #4418 (cherry picked from commit 10422f18285619f8f57b8b4ab5ca829eb21c115f) Conflicts: main/squashfs-tools/APKBUILD
* main/squashfs-tools: fix variable length array overflowNatanael Copa2015-08-052-6/+32
| | | | | | | | | | | | we can not guarantee that block size specified in user data will not overflow the stack so we need to use malloc. this fixes segfault when doing unsquashfs (cherry picked from commit 2fafe3d1eb933216776b191c85565ec5289161da) Conflicts: main/squashfs-tools/APKBUILD
* main/qemu: security fix for CVE-2015-5154Natanael Copa2015-08-052-1/+180
| | | | fixes #4496
* main/qemu: security fix for CVE-2015-4037Natanael Copa2015-08-052-1/+55
| | | | fixes #4326
* main/python: security upgrade to 2.7.10 (CVE-2014-9365)Natanael Copa2015-08-051-4/+4
| | | | fixes #3795
* main/net-snmp: security fix for CVE-2015-5621Natanael Copa2015-08-052-1/+138
| | | | fixes #4500
* main/ghostscript: security fix for CVE-2015-3228Natanael Copa2015-08-042-5/+39
| | | | fixes #4470
* main/bind: security upgrade to 9.10.2_p3 (CVE-2015-4620,CVE-2015-5477)Natanael Copa2015-08-041-4/+4
| | | | fixes #4507