Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/libtasn1: security fix (CVE-2018-6003) | Leonardo Arena | 2018-02-28 | 2 | -2/+78 | |
| | | | | Fixes #8530 | |||||
* | main/xen: security fixes | Leonardo Arena | 2018-02-28 | 5 | -2/+315 | |
| | | | | | | | | | CVE-2017-17566, XSA-248 CVE-2017-17563, XSA-249 CVE-2017-17564, XSA-250 CVE-2017-17565, XSA-251 Partially fixes #8523 | |||||
* | main/cups: fix CVE-2017-18190 | Natanael Copa | 2018-02-27 | 2 | -1/+29 | |
| | | | | fixes #8586 | |||||
* | main/libvorbis: security fixes (CVE-2017-14632, CVE-2017-14633) | dai9ah | 2018-02-27 | 3 | -2/+31 | |
| | | | | Fixes #8518 | |||||
* | main/curl: re-enable ssh support | Natanael Copa | 2018-02-27 | 1 | -1/+2 | |
| | | | | | | This was unintentionally disabled with the 7.58 upgrade. fixes #8577 | |||||
* | main/python2: security upgrade to 2.7.14 (CVE-2017-1000158) | Natanael Copa | 2018-02-22 | 1 | -4/+10 | |
| | | | | fixes #8543 | |||||
* | main/libxcursor: security upgrade to 1.1.15 (CVE-2017-16612) | Natanael Copa | 2018-02-20 | 1 | -5/+7 | |
| | | | | fixes #8230 | |||||
* | main/postgresql: security upgrade to 9.5.11 | Jakub Jirutka | 2018-02-09 | 1 | -4/+6 | |
| | ||||||
* | main/tiff: security fix CVE-2017-18013 | Leonardo Arena | 2018-02-08 | 2 | -4/+44 | |
| | | | | Fixes #8464 | |||||
* | main/bind: security upgrade to 9.10.6-P1 (CVE-2017-3145) | Leonardo Arena | 2018-02-08 | 1 | -5/+7 | |
| | | | | Fixes #8420 | |||||
* | main/curl: security upgrade to 7.58.0 | Leonardo Arena | 2018-02-08 | 1 | -6/+8 | |
| | | | | | | CVE-2018-1000005, CVE-2018-1000007 Fixes #8442 | |||||
* | main/php5: security upgrade to 5.6.33 | Leonardo Arena | 2018-02-07 | 1 | -4/+7 | |
| | | | | CVE-2018-5711 CVE-2018-5712 | |||||
* | main/libxml2: security upgrade to 2.9.5 (CVE-2017-16931) | Leonardo Arena | 2018-01-23 | 4 | -446/+8 | |
| | | | | Fixes #8399 | |||||
* | main/ncurses: security upgrade to 6.0-20171125 (CVE-2017-16879) | Leonardo Arena | 2018-01-23 | 1 | -4/+6 | |
| | | | | Fixes #8395 | |||||
* | main/awstats: security fix (CVE-2017-1000501) | Leonardo Arena | 2018-01-05 | 3 | -8/+156 | |
| | | | | Fixes #8375 | |||||
* | main/wget: security fixes (CVE-2017-13089, CVE-2017-13090) | Leonardo Arena | 2018-01-05 | 3 | -4/+84 | |
| | | | | Fixes #8076 | |||||
* | main/xen: security fixes | Leonardo Arena | 2018-01-05 | 20 | -1/+1689 | |
| | | | | | | | CVE-2017-15596, CVE-2017-15588, CVE-2017-15589, CVE-2017-15590, XSA-238 CVE-2017-15593, CVE-2017-15592, CVE-2017-15594, CVE-2017-15595, CVE-2017-15597 Fixes #8064 | |||||
* | main/xen: security fixes | Leonardo Arena | 2018-01-01 | 4 | -1/+371 | |
| | | | | | | CVE-2017-17044, CVE-2017-17045 Fixes #8222 | |||||
* | main/openssh: security fix (CVE-2017-15906) | Leonardo Arena | 2017-12-29 | 2 | -4/+35 | |
| | | | | Fixes #8285 | |||||
* | main/rsync: security fixes | Leonardo Arena | 2017-12-29 | 5 | -4/+159 | |
| | | | | | | CVE-2017-16548, CVE-2017-17433, CVE-2017-17434 Fixes #8321 | |||||
* | main/asterisk: security upgrade to 13.18.5 | Timo Teräs | 2017-12-29 | 1 | -4/+4 | |
| | | | | | | | | | | | fixes #8356 AST-2017-009 Buffer overflow in pjproject header parsing can cause crash AST-2017-010 Buffer overflow in CDR's set user AST-2017-011 Memory leak in pjsip session resource AST-2017-012 Remote Crash Vulnerability in RTCP Stack AST-2017-013 DOS Vulnerability in Asterisk chan_skinny AST-2017-014 Crash in PJSIP resource when missing a contact header | |||||
* | main/gd: security upgrade to 2.2.5 (CVE-2017-6362, CVE-2017-7890) | Leonardo Arena | 2017-12-28 | 1 | -4/+7 | |
| | | | | Fixes #8331 | |||||
* | main/ruby: security upgrade to 2.3.6 | Jakub Jirutka | 2017-12-15 | 1 | -2/+4 | |
| | | | | See: https://www.ruby-lang.org/en/news/2017/12/14/ruby-2-3-6-released/ | |||||
* | main/openssl: security upgrade to 1.0.2n | Colin Williams | 2017-12-15 | 1 | -4/+7 | |
| | | | | | | | | | fixes #8277 CVE-2017-3737 CVE-2017-3738 (cherry picked from commit b74e9ca7e1962c168d79fc1d11039d7febd5b0e6) | |||||
* | main/redis: upgrade to 3.2.11 | Jakub Jirutka | 2017-12-07 | 1 | -11/+2 | |
| | ||||||
* | main/libxfont: security upgrade to 1.5.4 (CVE-2017-16611) | Natanael Copa | 2017-12-07 | 1 | -4/+4 | |
| | | | | fixes #8226 | |||||
* | main/samba: fix CVE-2017-14746, CVE-2017-15275 | Natanael Copa | 2017-12-07 | 2 | -1/+118 | |
| | | | | fixes #8184 | |||||
* | main/ffmpeg: security upgrade to 3.1.11 | Natanael Copa | 2017-12-07 | 2 | -8/+118 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixes #8208 3.1.11 Fixes following vulnerabilities: CVE-2017-14054 CVE-2017-14055 CVE-2017-14056 CVE-2017-14057 CVE-2017-14058 CVE-2017-14059 CVE-2017-14169 CVE-2017-14170 CVE-2017-14171 CVE-2017-14222 CVE-2017-14223 CVE-2017-14225 CVE-2017-14767 3.1.10 Fixes following vulnerabilities: CVE-2017-11399 CVE-2017-11665 CVE-2017-11719 3.1.9 Fixes following vulnerabilities: CVE-2017-9993 3.1.8 Fixes following vulnerabilities: CVE-2017-9991 CVE-2017-9992 CVE-2017-9994 CVE-2017-9996 | |||||
* | main/curl: security upgrade to 7.57.0 | Natanael Copa | 2017-12-07 | 4 | -144/+9 | |
| | | | | | | | | CVE-2017-8816 CVE-2017-8817 CVE-2017-8818 fixes #8215 | |||||
* | main/pcre: add secfixes comment for CVE-2017-11164 | Natanael Copa | 2017-12-04 | 1 | -2/+4 | |
| | | | | | | | | We are not affected by CVE-2017-16231 due to our build with --with-match-limit-recursion=8192. We had this option since first commit, version 7.8, and were never affected. fixes #8142 | |||||
* | main/libvorbis: bump pkgrel and add secfixes comment | Natanael Copa | 2017-11-23 | 1 | -1/+5 | |
| | | | | really fixes #7940 | |||||
* | main/libvorbis: fix CVE-2017-14160 | Natanael Copa | 2017-11-23 | 2 | -12/+70 | |
| | | | | fixes #7939 | |||||
* | main/quagga: fix CVE-2017-16227 | Natanael Copa | 2017-11-23 | 2 | -1/+39 | |
| | | | | fixes #8085 | |||||
* | main/openvpn: security upgrade to 2.3.18 (CVE-2017-12166) | Natanael Copa | 2017-11-23 | 1 | -4/+4 | |
| | | | | fixes #8128 | |||||
* | main/varnish: fix secfixes comment | Natanael Copa | 2017-11-23 | 1 | -1/+1 | |
| | ||||||
* | main/postgresql: fix secfixes comment | Natanael Copa | 2017-11-23 | 1 | -1/+1 | |
| | ||||||
* | main/busybox: secfixes for CVE-2017-15873,CVE-2017-16544 | Natanael Copa | 2017-11-23 | 3 | -1/+262 | |
| | | | | fixes #8190 | |||||
* | main/tiff: security upgrade to 4.0.9 (CVE-2017-16231,CVE-2017-16232) | Natanael Copa | 2017-11-23 | 14 | -861/+7 | |
| | | | | fixes #8148 | |||||
* | main/varnish: security upgrade to 4.1.9 (CVE-2017-8807) | Natanael Copa | 2017-11-22 | 3 | -133/+22 | |
| | | | | fixes #8167 | |||||
* | main/postgresql: upgrade to 9.5.10 (security fixes) | Jakub Jirutka | 2017-11-21 | 1 | -5/+8 | |
| | | | | | | | | Fixes: CVE-2017-15098, CVE-2017-15099 Release Notes: https://www.postgresql.org/about/news/1801/ PostgreSQL on Alpine has never been affected by CVE-2017-12172. | |||||
* | main/openssl: security upgrade to 1.0.2m | Andy Postnikov | 2017-11-09 | 1 | -4/+7 | |
| | | | | | | | CVE-2017-3735 CVE-2017-3736 fixes #8116 | |||||
* | main/roundcubemail: security upgrade to 1.2.7 (CVE-2017-16651) | Leonardo Arena | 2017-11-09 | 1 | -5/+7 | |
| | ||||||
* | main/xen: add secinfo | Leonardo Arena | 2017-10-25 | 1 | -0/+13 | |
| | ||||||
* | main/xen: security upgrade to 4.6.6 | Leonardo Arena | 2017-10-25 | 43 | -3346/+461 | |
| | | | | | | (CVE-2017-12135, CVE-2017-12137, CVE-2017-12136, CVE-2017-12134, CVE-2017-12855) fixes #7734 | |||||
* | main/xen: update source | Leonardo Arena | 2017-10-25 | 1 | -2/+2 | |
| | ||||||
* | main/xen: security fixes | Leonardo Arena | 2017-10-25 | 5 | -1/+390 | |
| | | | | | | (CVE-2017-14316, CVE-2017-14317, CVE-2017-14318, CVE-2017-14319) fixes #7822 | |||||
* | main/gdk-pixbuf: security fix (CVE-2017-2862) | Leonardo Arena | 2017-10-25 | 2 | -4/+55 | |
| | | | | fixes #7868 | |||||
* | main/newsbeuter: security fix (CVE-2017-14500) | Leonardo Arena | 2017-10-24 | 2 | -5/+51 | |
| | | | | fixes #7879 | |||||
* | main/curl: security fix for CVE-2017-1000257 | Natanael Copa | 2017-10-24 | 2 | -4/+47 | |
| | | | | fixes #8041 | |||||
* | main/samba: security upgrade to 4.4.16 | Leonardo Arena | 2017-10-24 | 2 | -54/+12 | |
| | | | | | | (CVE-2017-12150, CVE-2017-12151, CVE-2017-12163) fixes #7894 |