Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/xen: security fixes. Fixes #6153 | Leonardo Arena | 2016-10-14 | 6 | -1/+361 | |
| | | | | | | | CVE-2016-7092, XSA-185: x86: Disallow L3 recursive pagetable for 32-bit PV guests¶ CVE-2016-7093, XSA-186: x86: Mishandling of instruction pointer truncation during emulation¶ CVE-2016-7094, XSA-187: x86 HVM: Overflow of sh_ctxt->seg_reg[]¶ CVE-2016-7154, XSA-188: use after free in FIFO event channel code | |||||
* | main/curl: security fix (CVE-2016-7141). Fixes #6135 | Leonardo Arena | 2016-10-14 | 2 | -5/+53 | |
| | ||||||
* | main/roundcubemail: upgrade to 1.1.6 | Leonardo Arena | 2016-10-12 | 1 | -4/+4 | |
| | ||||||
* | main/py-django: security upgrade to 1.8.15 | Kaarle Ritvanen | 2016-09-28 | 1 | -4/+4 | |
| | ||||||
* | main/libbsd: security upgrade to 0.8.2 (CVE-2016-2090). Fixes #6094 | Leonardo Arena | 2016-09-23 | 1 | -8/+12 | |
| | ||||||
* | main/openssl: upgrade to 1.0.2i | Natanael Copa | 2016-09-22 | 10 | -1376/+12 | |
| | | | | | | | | fixes #6208 - CVE-2016-2183 - CVE-2016-6304 - CVE-2016-6306 | |||||
* | main/owncloud: upgrade to 8.2.8 | Leonardo Arena | 2016-09-22 | 1 | -10/+10 | |
| | ||||||
* | main/openssl: fix patch for CVE-2016-2181 | Natanael Copa | 2016-09-19 | 2 | -5/+34 | |
| | | | | | Add a missing patch. ref #6178 | |||||
* | main/openssl: backport various secfixes | Natanael Copa | 2016-09-19 | 7 | -4/+930 | |
| | | | | | | | | | | fixes #6178 - CVE-2016-2179 - CVE-2016-2181 - CVE-2016-2182 - CVE-2016-6302 - CVE-2016-6303 | |||||
* | main/flex: security fix (CVE-2016-6354). Fixes #6089 | Leonardo Arena | 2016-09-14 | 2 | -5/+61 | |
| | ||||||
* | main/gd: security fixes. Fixes #6076 | Leonardo Arena | 2016-09-14 | 10 | -5/+495 | |
| | | | | | | | | | CVE-2015-8874 CVE-2016-5116 CVE-2016-5766 CVE-2016-6128 CVE-2016-6161 CVE-2016-6214 | |||||
* | main/libgcrypt: trac sec fix | Leonardo Arena | 2016-09-14 | 1 | -0/+3 | |
| | ||||||
* | main/libgcrypt: security upgrade to 1.6.6 (CVE-2016-6313). Fixes #6065 | Leonardo Arena | 2016-09-14 | 1 | -4/+4 | |
| | ||||||
* | main/wireshark: track more sec fixes | Leonardo Arena | 2016-09-13 | 1 | -0/+2 | |
| | | | | (cherry picked from commit 6ebfa63cc3b58907d0d1ba7e084b3bd455bc6e93) | |||||
* | main/wireshark: security upgrade to 2.0.5. Fixes #6052 | Leonardo Arena | 2016-09-12 | 1 | -4/+14 | |
| | | | | | | CVE-2016-6505, CVE-2016-6506, CVE-2016-6508, CVE-2016-6509, CVE-2016-6510, CVE-2016-6511 (cherry picked from commit e1d225fddc4d9dbb88b2f6f5bbcb4b00d04f5012) | |||||
* | main/openssl: fix for CVE-2016-2180 | Daniel Sabogal | 2016-09-09 | 2 | -4/+46 | |
| | | | | | | fixes #6117 (cherry picked from commit ecfc04f3961ec4ffa2c972bd72253ba1a03a3c1e) | |||||
* | main/php5: Upgrade to 5.6.25 | Andy Postnikov | 2016-08-23 | 1 | -4/+4 | |
| | ||||||
* | main/postgresql: security upgrade to 9.4.9 (CVE-2016-5423,CVE-2016-5424) | Natanael Copa | 2016-08-17 | 1 | -4/+4 | |
| | | | | fixes #6046 | |||||
* | main/openssh: security fix for CVE-2016-6515 | Natanael Copa | 2016-08-17 | 2 | -4/+60 | |
| | | | | fixes #6041 | |||||
* | main/fontconfig: security fix (CVE-2016-5384). Fixes #6025 | Leonardo Arena | 2016-08-15 | 2 | -5/+175 | |
| | ||||||
* | main/xen: security fixes (CVE-2016-6258, CVE-2016-6259, CVE-2016-5403) | Natanael Copa | 2016-08-12 | 5 | -1/+290 | |
| | | | | | | fixes #6018 (cherry picked from commit d0a7fcca4e82f4ff531083fa762975ee6b0ec9f4) | |||||
* | main/curl: security fixes (CVE-2016-5419, CVE-2016-5420, CVE-2016-5421) | Leonardo Arena | 2016-08-12 | 4 | -5/+174 | |
| | | | | Fixes #6005 | |||||
* | main/dropbear: security upgrade to 2016.74. Fixes #5996 | Leonardo Arena | 2016-08-12 | 1 | -4/+10 | |
| | ||||||
* | main/owncloud: upgrade to 8.2.7 | Leonardo Arena | 2016-08-11 | 1 | -10/+10 | |
| | ||||||
* | main/collectd: security upgrade to 5.5.2 (CVE-2016-6254). Fixes #5990 | Leonardo Arena | 2016-08-08 | 2 | -20/+10 | |
| | | | | (cherry picked from commit ac94d4b9a3edac9db7aa1481b4866cb39d032843) | |||||
* | main/libarchive: security fixes. Fixes #5972 | Leonardo Arena | 2016-08-08 | 5 | -4/+203 | |
| | | | | | | | CVE-2016-4302 CVE-2016-4809 CVE-2016-5844 CVE-2016-6250 | |||||
* | main/libidn: security upgrade to 1.33. Fixes #5967 | Leonardo Arena | 2016-08-05 | 1 | -5/+18 | |
| | | | | | | (CVE-2016-6263, CVE-2015-8948, CVE-2016-6262, CVE-2016-6261) (cherry picked from commit 87698baa9ec19d0554e5233954b6f266efe8b5cd) | |||||
* | main/cacti: security fix (CVE-2016-3172). Fixes #5941 | Leonardo Arena | 2016-08-05 | 2 | -4/+24 | |
| | ||||||
* | main/openssh: security fix (CVE-2016-6210). Fixes #5927 | Leonardo Arena | 2016-08-05 | 3 | -5/+232 | |
| | ||||||
* | main/libvirt: security fix (CVE-2016-5008). Fixes #5876 | Leonardo Arena | 2016-08-01 | 2 | -4/+80 | |
| | ||||||
* | main/squid: security upgrade to 3.5.18 | Leonardo Arena | 2016-07-29 | 1 | -4/+4 | |
| | | | | | | CVE-2016-4553: Cache poisoning issue in HTTP Request handling CVE-2016-4554: Header smuggling issue in HTTP Request processing CVE-2016-4555, CVE-2016-4556: Multiple Denial of Service issues in ESI Response processing | |||||
* | main/php5: Upgrade to 5.6.24 | Andy Postnikov | 2016-07-27 | 1 | -4/+4 | |
| | | | | fixes #5958 | |||||
* | main/bind: security upgrade to 9.10.4_p2 (CVE-2016-2775) | Natanael Copa | 2016-07-25 | 1 | -4/+4 | |
| | | | | fixes #5953 | |||||
* | main/apache2: security fix for CVE-2016-5387 | Natanael Copa | 2016-07-25 | 2 | -4/+25 | |
| | | | | fixes #5937 | |||||
* | main/samba: security upgrade to 4.2.14 (CVE-2016-2119) | Natanael Copa | 2016-07-22 | 1 | -4/+4 | |
| | | | | fixes #5946 | |||||
* | main/tevent: upgrade to 0.9.28 | Natanael Copa | 2016-07-22 | 1 | -4/+4 | |
| | | | | | samba 4.2.14 requires tevent 0.9.28 ref #5946 | |||||
* | main/dnsmasq: security upgrade to 2.76 (CVE-2015-8899) | Natanael Copa | 2016-07-20 | 1 | -5/+5 | |
| | | | | fixes #5923 | |||||
* | main/gimp: security upgrade to 2.8.18 (CVE-2016-4994) | Natanael Copa | 2016-07-20 | 1 | -4/+4 | |
| | | | | fixes #5860 | |||||
* | main/py-django: fix download url | Natanael Copa | 2016-07-19 | 1 | -1/+1 | |
| | ||||||
* | main/py-django: security upgrade to 1.8.14 (CVE-2016-6186) | Natanael Copa | 2016-07-19 | 1 | -4/+4 | |
| | | | | fixes #5913 | |||||
* | main/acf-freeswitch-vmail: upgrade to 0.6.2 | Ted Trask | 2016-07-15 | 1 | -5/+5 | |
| | | | | (cherry picked from commit b117bf08c5cb8e96b78c679d10bc030321c9cbf5) | |||||
* | main/mini_httpd: security upgrade to 1.23 (CVE-2015-1548) | Natanael Copa | 2016-07-14 | 1 | -5/+5 | |
| | | | | fixes #5902 | |||||
* | main/apache2: new upstream version 2.4.23 | Christian Kampka | 2016-07-13 | 1 | -4/+4 | |
| | ||||||
* | main/apache2: upgrade to 2.4.20 | Kaarle Ritvanen | 2016-07-13 | 1 | -5/+5 | |
| | ||||||
* | main/apache2: recompile broken suEXEC | steffen@stelas.de | 2016-07-13 | 1 | -3/+3 | |
| | | | | | | | | Fixing two issues regarding suEXEC: - suEXEC compiles with correct Apache user - set docroot to /var/www - needed for virtual hosts ref #5500 | |||||
* | main/apache2: upgrade to 2.4.18 | Kaarle Ritvanen | 2016-07-13 | 15 | -91/+84 | |
| | ||||||
* | main/apache2: fix indented LoadModule paths | Kaarle Ritvanen | 2016-07-13 | 1 | -2/+2 | |
| | ||||||
* | main/apache2: fix module paths in dav.conf, ssl.conf | Kaarle Ritvanen | 2016-07-13 | 2 | -12/+12 | |
| | ||||||
* | main/acf-provisioning: upgrade to 0.8.13 | Ted Trask | 2016-07-08 | 1 | -4/+4 | |
| | ||||||
* | main/wget: security backport (CVE-2016-4971) | Bartłomiej Piotrowski | 2016-07-05 | 2 | -5/+296 | |
| |