aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/tiff: security fixes. Fixes #5825Leonardo Arena2016-07-044-5/+351
| | | | | | | | | | | CVE-2015-8665 CVE-2015-8683 CVE-2015-8781 CVE-2015-8782 CVE-2015-8784 (cherry picked from commit 7f2845dc97725af0dc4230433d9cb42a76c552db) (cherry picked from commit df6ff3e3449ac74fc39165229f9764d968aa58f4)
* main/py-pygments: security fix for CVE-2015-8557Natanael Copa2016-07-042-6/+44
| | | | | | fixes #5817 (cherry picked from commit 77c394877f06aa34a90863e93055d689aa1b1f9e)
* main/jansson: security fix for CVE-2016-4425Natanael Copa2016-07-042-6/+148
| | | | | | fixes #5792 (cherry picked from commit 36ab20a1ac9047916d193fc1aae1cf8be6b0ee23)
* main/libksba: security upgrade to 1.3.4. Fixes #5781Leonardo Arena2016-07-041-4/+13
|
* main/owncloud: upgrade to 8.2.6Leonardo Arena2016-07-011-10/+10
|
* main/python: security upgrade to 2.7.12Natanael Copa2016-06-291-5/+5
| | | | | | | | CVE-2016-0772: smtplib StartTLS stripping attack. CVE-2016-5636: Heap overflow in zipimporter module . CVE-2016-5699: HTTP header injection in urrlib2/urllib/httplib/http.client. fixes #5801
* main/py-django: upgrade to 1.8.12Kaarle Ritvanen2016-06-281-4/+4
|
* main/haproxy: security upgrade to 1.6.6 (CVE-2016-5360)Natanael Copa2016-06-271-4/+4
| | | | fixes #5813
* main/nss: security upgrade to 3.23 (CVE-2016-2834)Natanael Copa2016-06-241-4/+4
| | | | fixes #5733
* main/nspr: upgrade to 4.12Natanael Copa2016-06-242-10/+9
| | | | | needed by nss-3.23 ref #5733
* main/giflib: security fix (CVE-2015-7555). Fixes #5660Leonardo Arena2016-06-242-1/+31
|
* main/xen: security upgrade to 4.6.3. Fixes #5776Leonardo Arena2016-06-249-967/+5
| | | | | | | | | | | | | | | | | CVE-2016-4962, XSA-175: Unsanitised guest input in libxl device handling code http://xenbits.xen.org/xsa/advisory-175.html CVE-2016-4480, XSA-176: x86 software guest page walk PS bit handling flaw http://xenbits.xen.org/xsa/advisory-176.html CVE-2016-4963, XSA-178: Unsanitised driver domain input in libxl device handling http://xenbits.xen.org/xsa/advisory-178.html CVE-2016-3710 CVE-2016-3712, XSA-179: QEMU: Banked access to VGA memory (VBE) uses inconsistent bounds checks http://xenbits.xen.org/xsa/advisory-179.html CVE-2014-3672, XSA-180: Unrestricted qemu logging http://xenbits.xen.org/xsa/advisory-180.html
* main/libxslt: security upgrade to 1.1.29 (CVE-2015-7995, CVE-2016-1683, ↵Leonardo Arena2016-06-231-11/+7
| | | | CVE-2016-1684). Fixes #5754
* main/vlc: security upgrade to 2.2.4 (CVE-2016-5108). Fixes #5716Leonardo Arena2016-06-231-9/+5
|
* main/nginx: security fix (CVE-2016-4450). Fixes #5676Leonardo Arena2016-06-232-4/+23
|
* community/claws-mail: security upgrade to 3.13.1 (CVE-2015-8614). Fixes #5658Leonardo Arena2016-06-231-4/+4
|
* main/openssl: security fix for CVE-2016-2177, CVE-2016-2178Natanael Copa2016-06-223-4/+395
|
* main/busybox: upgrade to 1.24.2, fix CVE-2016-2147,CVE-2016-2148Natanael Copa2016-06-225-258/+140
| | | | (cherry picked from commit 6ad5097ddbca9754f6a9aa3833090534baff76a6)
* main/hostapd: security fix for CVE-2016-4476Natanael Copa2016-06-222-1/+87
| | | | fixes #5646
* main/hostapd: enable automatic channel selectionStefan Wagner2016-06-221-1/+2
| | | | (cherry picked from commit 1dc3d131f36dc307adb248f89377a0f585263eb2)
* main/curl: security upgrade to 7.49.1 (CVE-2016-3739)Natanael Copa2016-06-221-4/+4
| | | | fixes #5651
* main/jq: security fix (CVE-2015-8863). Fixes #5633Leonardo Arena2016-06-212-5/+56
|
* main/wireshark: security upgrade to 2.0.4Leonardo Arena2016-06-211-4/+4
| | | | | | | | | | | | | | | | CVE-2016-4076 CVE-2016-4077 CVE-2016-4083 CVE-2016-4084 CVE-2016-4006 CVE-2016-4078 CVE-2016-4079 CVE-2016-4080 CVE-2016-4081 CVE-2016-4082 Fixes #5622 Fixes #5624
* main/gd: security fix (CVE-2016-3074). Fixes #5610Leonardo Arena2016-06-213-5/+100
|
* main/phpmyadmin: security upgrade to 4.5.5.1. Fixes #5606Leonardo Arena2016-06-211-4/+4
| | | | (CVE-2016-2559, CVE-2016-2560, CVE-2016-2561, CVE-2016-2562)
* main/expat: security fix (CVE-2016-0718). Fixes #5597Leonardo Arena2016-06-212-5/+766
|
* main/imagemagick: security upgrade to 6.9.3.10. Fixes #5552Leonardo Arena2016-06-211-5/+5
| | | | (CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717, CVE-2016-3718)
* main/libarchive: security fix (CVE-2016-1541). Fixes #5562Leonardo Arena2016-06-142-4/+76
|
* main/poppler: security fix (CVE-2015-8868). Fixes #5534Leonardo Arena2016-06-142-9/+44
|
* main/subversion: security upgrade to 1.9.4 (CVE-2016-2167, CVE-2016-2168). ↵Leonardo Arena2016-06-141-4/+4
| | | | Fixes #5528
* main/giflib: security fix (CVE-2016-3977). Fixes #5514Leonardo Arena2016-06-142-5/+92
|
* main/libxml2: security upgrade to 2.9.4Natanael Copa2016-06-141-4/+4
| | | | | | | | | | | | | | | | | | | | | | Fixes: CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-2073 (NOTE: same fix as CVE-2016-1839) CVE-2016-3627 CVE-2016-3705 CVE-2016-4483 fixes #5441 (cherry picked from commit 8aa7dd816ba978268e23e1e87cd0942e65be872c) Signed-off-by: Leonardo Arena <rnalrd@alpinelinux.org>
* main/acf-openssh: upgrade to 0.11.1Ted Trask2016-06-101-4/+4
| | | | (cherry picked from commit 026a9ad1a5dce76d0715721da8c190f7aaf7f98d)
* main/wpa_supplicant: security fix for CVE-2016-4476, CVE-2016-4477Natanael Copa2016-05-306-1/+348
| | | | fixes #5639
* main/vim: fix permissions of vimrcNatanael Copa2016-05-261-2/+2
| | | | | | ref #5592 (cherry picked from commit e846fdda4eb9806c36115bd24242c2d5cef4eb98)
* main/wpa_supplicant: fix config permissionsNatanael Copa2016-05-261-3/+3
| | | | | | ref #5592 (cherry picked from commit d36045ec2d54bba93140a56c2382256dcfa44e16)
* main/owncloud: upgrade to 8.2.5Leonardo Arena2016-05-261-11/+11
|
* main/nfdump: fix security issue and shared libsLeonardo Arena2016-05-193-1/+1294
| | | | (cherry picked from commit 67d6ce49c6349f7f1316aca24ecbec22c5c2b444)
* main/nfdump: upgrade to 1.6.14Leonardo Arena2016-05-191-8/+8
| | | | (cherry picked from commit 53e00664fe3d77ee856eacd08f91836319a4745f)
* main/mercurial: security fix for CVE-2016-3105Natanael Copa2016-05-162-5/+48
| | | | fixes #5573
* main/privoxy: fix docdirNatanael Copa2016-05-161-1/+2
| | | | fixes #5566
* main/dtach: fix docdirNatanael Copa2016-05-161-4/+7
| | | | | | ref #5566 (cherry picked from commit c92b773b2ce3e53ca5e0420cb4ac482c832a3096)
* community/openjdk8: security upgrade to 8u92Natanael Copa2016-05-102-35/+35
| | | | | | | | | CVE-2016-0686 CVE-2016-0687 CVE-2016-0695 CVE-2016-3425 CVE-2016-3426 CVE-2016-3427
* main/expat: new upstream version 2.1.1 (CVE-2015-1283)Christian Kampka2016-05-101-6/+6
|
* main/owncloud: fix checksumsLeonardo Arena2016-05-101-4/+4
|
* main/owncloud: upgrade to 8.2.4Leonardo Arena2016-05-102-12/+12
|
* main/squid: security upgrade to 3.5.17. Fixes #5508Leonardo Arena2016-05-091-9/+5
| | | | (CVE-2016-3947, CVE-2016-3948, CVE-2016-4051, CVE-2016-4052, CVE-2016-4053, CVE-2016-4054)
* main/samba: security upgrade to 4.2.11. Fixes #5496Leonardo Arena2016-05-091-4/+4
| | | | | | | | | | | CVE-2015-5370 CVE-2016-2110 CVE-2016-2111 CVE-2016-2112 CVE-2016-2113 CVE-2016-2114 CVE-2016-2115 CVE-2016-2118
* main/xen: security fixes (CVE-2016-3158, CVE-2016-3159, CVE-2016-3960). ↵Leonardo Arena2016-05-093-1/+292
| | | | | | Fixes #5490 (cherry picked from commit 40a3ee6c24583c262a4a8390459526dc40832862)
* main/pcre: several fixes including CVEs (CVE-2016-1283, CVE-2016-3191). ↵Leonardo Arena2016-05-092-5/+1418
| | | | | | Fixes #5473 (cherry picked from commit 1cabd618771bbdcfb71da232ac9b9d5719e62ec3)