Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/postgresql: security upgrade to 9.3.11 (CVE-2016-0766, CVE-2016-0773). ↵ | Leonardo Arena | 2016-02-16 | 1 | -4/+4 | |
| | | | | Fixes #5122 | |||||
* | main/cgit: upgrade to 0.10.2. Security fixes for CVE-2016-1899, ↵ | Leonardo Arena | 2016-02-11 | 5 | -12/+221 | |
| | | | | | | CVE-2016-1900, CVE-2016-1901. Fixes #5099 (cherry picked from commit b4162b52de066db4f8df3ff8ceceac451f0c3c7e) | |||||
* | main/privoxy: security upgrade to 3.0.24 (CVE-2016-1982,CVE-2016-1983). ↵ | Leonardo Arena | 2016-02-09 | 1 | -4/+4 | |
| | | | | | | Fixes #5063 (cherry picked from commit 3abe44615ddc514b7298119cef64498d06be639f) | |||||
* | main/php: security upgrade to 5.5.32 | Kaarle Ritvanen | 2016-02-05 | 1 | -4/+4 | |
| | ||||||
* | main/openssl: security upgrade to 1.0.1r | Timo Teräs | 2016-01-28 | 1 | -4/+4 | |
| | | | | | | Fixes CVE-2015-3197 (cherry picked from commit 82dae76b434b656e0fe9d8dffff5037059d25559) | |||||
* | main/bind: security upgrade to 9.10.3_p3 (CVE-2015-8704,CVE-2015-8705). ↵ | Leonardo Arena | 2016-01-27 | 1 | -4/+4 | |
| | | | | | | Fixes #5037 (cherry picked from commit 1cff01908c342a676deca5a1d7261020c6241d2d) | |||||
* | main/libpng: security upgrade to 1.6.20 (CVE-2015-8472). Fixes #5023 | Leonardo Arena | 2016-01-27 | 1 | -7/+7 | |
| | ||||||
* | main/cacti: security fix CVE-2015-8369. #4997 | Leonardo Arena | 2016-01-27 | 2 | -4/+212 | |
| | | | | (cherry picked from commit f2790debf25f0b5bcd813f4b67e771465afe6877) | |||||
* | main/php: security upgrade to 5.5.31 | Kaarle Ritvanen | 2016-01-25 | 1 | -4/+4 | |
| | ||||||
* | main/dhcp: security upgrade to 4.3.3_p1 | Leonardo Arena | 2016-01-15 | 1 | -9/+5 | |
| | ||||||
* | main/openssh: security fix for CVE-2016-0777 and CVE-2016-0778 | Natanael Copa | 2016-01-14 | 2 | -1/+45 | |
| | | | | | | | | | | | | | | | | | | CVE-2016-0777 An information leak (memory disclosure) can be exploited by a rogue SSH server to trick a client into leaking sensitive data from the client memory, including for example private keys. CVE-2016-0778 A buffer overflow (leading to file descriptor leak), can also be exploited by a rogue SSH server, but due to another bug in the code is possibly not exploitable, and only under certain conditions (not the default configuration), when using ProxyCommand, ForwardAgent or ForwardX11. fixes #5018 | |||||
* | main/acf-weblog: upgrade to 0.10.5 | Ted Trask | 2015-12-30 | 1 | -4/+4 | |
| | | | | (cherry picked from commit 90307c81ab6049080934fb67cb2b5352f5fc07bc) | |||||
* | main/ipfw-grsec: rebuild against kernel 3.14.22-r2 | Leonardo Arena | 2015-12-30 | 1 | -1/+1 | |
| | ||||||
* | main/dahdi-linux-grsec: rebuild against kernel 3.14.22-r2 | Leonardo Arena | 2015-12-30 | 1 | -1/+1 | |
| | ||||||
* | main/xtables-addons-grsec: rebuild against kernel 3.14.22-r2 | Leonardo Arena | 2015-12-30 | 1 | -1/+1 | |
| | ||||||
* | main/flashcache-grsec: rebuild against kernel 3.14.22-r2 | Leonardo Arena | 2015-12-30 | 1 | -1/+1 | |
| | ||||||
* | main/linux-grsec: security fix CVE-2015-1333. Fixes #4599 | Leonardo Arena | 2015-12-30 | 2 | -1/+54 | |
| | ||||||
* | main/roundcubemail: security upgrade to 1.0.8 | Leonardo Arena | 2015-12-29 | 1 | -4/+4 | |
| | | | | | https://www.htbridge.com/advisory/HTB23283 (cherry picked from commit 7a165272eb73d755a0e3f1234c53eacc5ff6ceb1) | |||||
* | main/acf-core: upgrade to 0.18.11 | Ted Trask | 2015-12-24 | 1 | -4/+4 | |
| | | | | (cherry picked from commit 6503c466f0b87266e175d44fc51d5b3127bf0f3d) | |||||
* | main/bind: security upgrade to 9.10.3_p2 (CVE-2015-8461,CVE-2015-8000) | Natanael Copa | 2015-12-16 | 1 | -4/+4 | |
| | | | | fixes #4959 | |||||
* | main/redis: upgrade to 2.8.23 and security fix for CVE-2015-8080 | Natanael Copa | 2015-12-16 | 2 | -9/+65 | |
| | | | | | ref #4943 fixes #4947 | |||||
* | main/libsndfile: security upgrade to 1.0.26 (CVE-2015-7805) | Natanael Copa | 2015-12-16 | 1 | -4/+5 | |
| | | | | fixes #4942 | |||||
* | main/gdk-pixbuf: security upgrade to 2.32.2 | Natanael Copa | 2015-12-16 | 1 | -5/+6 | |
| | | | | | ref #4733 fixes #4737 | |||||
* | main/krb5: upgrade to 1.12.4 and fix CVE-2014-5351, CVE-2015-2698 | Natanael Copa | 2015-12-09 | 6 | -114/+341 | |
| | | | | | fixes #3802 fixes #4838 | |||||
* | main/krb5: security fixes (CVE-2015-2694, CVE-2015-2695, CVE-2015-2696, ↵ | Christian Kampka | 2015-12-09 | 5 | -2/+1464 | |
| | | | | | | CVE-2015-2697) fixes: #4838 | |||||
* | main/cups-filters: security fix CVE-2015-8327. Fixes #4932 | Leonardo Arena | 2015-12-09 | 2 | -4/+27 | |
| | ||||||
* | main/openssl: security release 1.0.1q | Christian Kampka | 2015-12-04 | 2 | -150/+137 | |
| | ||||||
* | main/freeradius: security upgrade to 2.2.9 (CVE-2015-4680). Fixes #4379 | Leonardo Arena | 2015-12-04 | 2 | -21/+5 | |
| | ||||||
* | main/rsyslog: fix default permissions (CVE-2015-3243). Fixes #4408 | Natanael Copa | 2015-12-04 | 2 | -4/+11 | |
| | ||||||
* | main/rt4: security fix CVE-2015-5475. Fixes #4524 | Leonardo Arena | 2015-12-04 | 2 | -4/+68 | |
| | ||||||
* | main/cyrus-sasl: security fix for CVE-2013-4122. Fixes #4699 | Leonardo Arena | 2015-12-04 | 2 | -4/+126 | |
| | ||||||
* | main/strongswan: security fix CVE-2015-8023. Fixes #4879 | Leonardo Arena | 2015-12-04 | 2 | -5/+44 | |
| | ||||||
* | main/xen: fix various vulnerabilities #4748 | Leonardo Arena | 2015-12-03 | 13 | -141/+627 | |
| | ||||||
* | main/ruby: security upgrade to 2.0.0_p647 (CVE-2015-3900). Fixes #4788 | Leonardo Arena | 2015-12-03 | 1 | -4/+4 | |
| | ||||||
* | main/pixman: security upgrade to 0.32.8. Fixes #4793 | Leonardo Arena | 2015-12-03 | 1 | -4/+4 | |
| | ||||||
* | main/libvdpau: security fixes CVE-2015-5198, CVE-2015-5199, CVE-2015-5200. ↵ | Leonardo Arena | 2015-12-03 | 2 | -6/+231 | |
| | | | | Fixes #4823 | |||||
* | main/cups-filters: security fix CVE-2015-3279. Fixes #4820 | Leonardo Arena | 2015-12-03 | 2 | -4/+112 | |
| | ||||||
* | main/putty: update checksum | Leonardo Arena | 2015-12-03 | 1 | -1/+10 | |
| | ||||||
* | main/putty: security upgrade to 0.66 (CVE-2015-5309). Fixes #4912 | Leonardo Arena | 2015-12-03 | 3 | -5/+31 | |
| | ||||||
* | main/squid: security upgrade to 3.4.14 (CVE-2015-3455,CVE-2015-5400) | Natanael Copa | 2015-12-02 | 1 | -4/+4 | |
| | | | | | fixes #4224 fixes #4709 | |||||
* | main/phpmyadmin: security upgrade to 4.2.13.3 | Natanael Copa | 2015-12-02 | 1 | -5/+5 | |
| | | | | | | | | CVE-2015-2206 CVE-2015-3902 CVE-2015-3903 fixes #4806 | |||||
* | main/postgresql: security upgrade 9.3.10 (CVE-2015-5288, CVE-2015-5289) | Christian Kampka | 2015-12-01 | 1 | -5/+5 | |
| | | | | fixes #4783 | |||||
* | main/xscreensaver: security upgrade to 5.34 (CVE-2015-8025) | Natanael Copa | 2015-11-30 | 1 | -4/+4 | |
| | | | | fixes #4829 | |||||
* | main/libxml2: security fixes | Christian Kampka | 2015-11-30 | 14 | -5/+816 | |
| | | | | | | | | | | | | | | | | | | CVE-2015-8242 Buffer overead with HTML parser in push mode (Hugh Davenport) CVE-2015-7500 Fix memory access error due to incorrect entities boundaries (Daniel Veillard) CVE-2015-7499-2 Detect incoherency on GROW (Daniel Veillard) CVE-2015-7499-1 Add xmlHaltParser() to stop the parser (Daniel Veillard) CVE-2015-5312 Another entity expansion issue (David Drysdale) CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey (David Drysdale) CVE-2015-7498 Avoid processing entities after encoding conversion failures (Daniel Veillard) CVE-2015-8035 Fix XZ compression support loop (Daniel Veillard) CVE-2015-7942-2 Fix an error in previous Conditional section patch (Daniel Veillard) CVE-2015-7942 Another variation of overflow in Conditional sections (Daniel Veillard) CVE-2015-1819 Enforce the reader to run in constant memory (Daniel Veillard) CVE-2015-7941_2 Cleanup conditional section error handling (Daniel Veillard) CVE-2015-7941_1 Stop parsing on entities boundaries errors (Daniel Veillard) fixes #4800 | |||||
* | main/sqlite: bump pkgrel | Natanael Copa | 2015-11-30 | 1 | -1/+1 | |
| | | | | so we get the -dev fix | |||||
* | main/nspr: use http for source url | Natanael Copa | 2015-11-30 | 1 | -1/+1 | |
| | ||||||
* | main/nss: use http for source url | Natanael Copa | 2015-11-30 | 1 | -1/+1 | |
| | ||||||
* | main/nss: security upgrade to 3.19.2.1 | Natanael Copa | 2015-11-30 | 1 | -4/+4 | |
| | | | | | | | | | | CVE-2015-2721 CVE-2015-2730 CVE-2015-7181 CVE-2015-7182 fixes #4720 fixes #4845 | |||||
* | main/sqlite: fix -dev package | Natanael Copa | 2015-11-30 | 1 | -19/+0 | |
| | ||||||
* | main/nspr: security upgrade to 4.10.10 (CVE-2015-7183) | Natanael Copa | 2015-11-30 | 1 | -5/+5 | |
| | | | | fixes #4850 |