aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/libtasn1: security fix (CVE-2018-6003)Leonardo Arena2018-02-282-2/+78
| | | | Fixes #8530
* main/xen: security fixesLeonardo Arena2018-02-285-2/+315
| | | | | | | | | CVE-2017-17566, XSA-248 CVE-2017-17563, XSA-249 CVE-2017-17564, XSA-250 CVE-2017-17565, XSA-251 Partially fixes #8523
* main/cups: fix CVE-2017-18190Natanael Copa2018-02-272-1/+29
| | | | fixes #8586
* main/libvorbis: security fixes (CVE-2017-14632, CVE-2017-14633)dai9ah2018-02-273-2/+31
| | | | Fixes #8518
* main/curl: re-enable ssh supportNatanael Copa2018-02-271-1/+2
| | | | | | This was unintentionally disabled with the 7.58 upgrade. fixes #8577
* main/python2: security upgrade to 2.7.14 (CVE-2017-1000158)Natanael Copa2018-02-221-4/+10
| | | | fixes #8543
* main/libxcursor: security upgrade to 1.1.15 (CVE-2017-16612)Natanael Copa2018-02-201-5/+7
| | | | fixes #8230
* main/postgresql: security upgrade to 9.5.11Jakub Jirutka2018-02-091-4/+6
|
* main/tiff: security fix CVE-2017-18013Leonardo Arena2018-02-082-4/+44
| | | | Fixes #8464
* main/bind: security upgrade to 9.10.6-P1 (CVE-2017-3145)Leonardo Arena2018-02-081-5/+7
| | | | Fixes #8420
* main/curl: security upgrade to 7.58.0Leonardo Arena2018-02-081-6/+8
| | | | | | CVE-2018-1000005, CVE-2018-1000007 Fixes #8442
* main/php5: security upgrade to 5.6.33Leonardo Arena2018-02-071-4/+7
| | | | CVE-2018-5711 CVE-2018-5712
* main/libxml2: security upgrade to 2.9.5 (CVE-2017-16931)Leonardo Arena2018-01-234-446/+8
| | | | Fixes #8399
* main/ncurses: security upgrade to 6.0-20171125 (CVE-2017-16879)Leonardo Arena2018-01-231-4/+6
| | | | Fixes #8395
* main/awstats: security fix (CVE-2017-1000501)Leonardo Arena2018-01-053-8/+156
| | | | Fixes #8375
* main/wget: security fixes (CVE-2017-13089, CVE-2017-13090)Leonardo Arena2018-01-053-4/+84
| | | | Fixes #8076
* main/xen: security fixesLeonardo Arena2018-01-0520-1/+1689
| | | | | | | CVE-2017-15596, CVE-2017-15588, CVE-2017-15589, CVE-2017-15590, XSA-238 CVE-2017-15593, CVE-2017-15592, CVE-2017-15594, CVE-2017-15595, CVE-2017-15597 Fixes #8064
* main/xen: security fixesLeonardo Arena2018-01-014-1/+371
| | | | | | CVE-2017-17044, CVE-2017-17045 Fixes #8222
* main/openssh: security fix (CVE-2017-15906)Leonardo Arena2017-12-292-4/+35
| | | | Fixes #8285
* main/rsync: security fixesLeonardo Arena2017-12-295-4/+159
| | | | | | CVE-2017-16548, CVE-2017-17433, CVE-2017-17434 Fixes #8321
* main/asterisk: security upgrade to 13.18.5Timo Teräs2017-12-291-4/+4
| | | | | | | | | | | fixes #8356 AST-2017-009 Buffer overflow in pjproject header parsing can cause crash AST-2017-010 Buffer overflow in CDR's set user AST-2017-011 Memory leak in pjsip session resource AST-2017-012 Remote Crash Vulnerability in RTCP Stack AST-2017-013 DOS Vulnerability in Asterisk chan_skinny AST-2017-014 Crash in PJSIP resource when missing a contact header
* main/gd: security upgrade to 2.2.5 (CVE-2017-6362, CVE-2017-7890)Leonardo Arena2017-12-281-4/+7
| | | | Fixes #8331
* main/ruby: security upgrade to 2.3.6Jakub Jirutka2017-12-151-2/+4
| | | | See: https://www.ruby-lang.org/en/news/2017/12/14/ruby-2-3-6-released/
* main/openssl: security upgrade to 1.0.2nColin Williams2017-12-151-4/+7
| | | | | | | | | fixes #8277 CVE-2017-3737 CVE-2017-3738 (cherry picked from commit b74e9ca7e1962c168d79fc1d11039d7febd5b0e6)
* main/redis: upgrade to 3.2.11Jakub Jirutka2017-12-071-11/+2
|
* main/libxfont: security upgrade to 1.5.4 (CVE-2017-16611)Natanael Copa2017-12-071-4/+4
| | | | fixes #8226
* main/samba: fix CVE-2017-14746, CVE-2017-15275Natanael Copa2017-12-072-1/+118
| | | | fixes #8184
* main/ffmpeg: security upgrade to 3.1.11Natanael Copa2017-12-072-8/+118
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixes #8208 3.1.11 Fixes following vulnerabilities: CVE-2017-14054 CVE-2017-14055 CVE-2017-14056 CVE-2017-14057 CVE-2017-14058 CVE-2017-14059 CVE-2017-14169 CVE-2017-14170 CVE-2017-14171 CVE-2017-14222 CVE-2017-14223 CVE-2017-14225 CVE-2017-14767 3.1.10 Fixes following vulnerabilities: CVE-2017-11399 CVE-2017-11665 CVE-2017-11719 3.1.9 Fixes following vulnerabilities: CVE-2017-9993 3.1.8 Fixes following vulnerabilities: CVE-2017-9991 CVE-2017-9992 CVE-2017-9994 CVE-2017-9996
* main/curl: security upgrade to 7.57.0Natanael Copa2017-12-074-144/+9
| | | | | | | | CVE-2017-8816 CVE-2017-8817 CVE-2017-8818 fixes #8215
* main/pcre: add secfixes comment for CVE-2017-11164Natanael Copa2017-12-041-2/+4
| | | | | | | | We are not affected by CVE-2017-16231 due to our build with --with-match-limit-recursion=8192. We had this option since first commit, version 7.8, and were never affected. fixes #8142
* main/libvorbis: bump pkgrel and add secfixes commentNatanael Copa2017-11-231-1/+5
| | | | really fixes #7940
* main/libvorbis: fix CVE-2017-14160Natanael Copa2017-11-232-12/+70
| | | | fixes #7939
* main/quagga: fix CVE-2017-16227Natanael Copa2017-11-232-1/+39
| | | | fixes #8085
* main/openvpn: security upgrade to 2.3.18 (CVE-2017-12166)Natanael Copa2017-11-231-4/+4
| | | | fixes #8128
* main/varnish: fix secfixes commentNatanael Copa2017-11-231-1/+1
|
* main/postgresql: fix secfixes commentNatanael Copa2017-11-231-1/+1
|
* main/busybox: secfixes for CVE-2017-15873,CVE-2017-16544Natanael Copa2017-11-233-1/+262
| | | | fixes #8190
* main/tiff: security upgrade to 4.0.9 (CVE-2017-16231,CVE-2017-16232)Natanael Copa2017-11-2314-861/+7
| | | | fixes #8148
* main/varnish: security upgrade to 4.1.9 (CVE-2017-8807)Natanael Copa2017-11-223-133/+22
| | | | fixes #8167
* main/postgresql: upgrade to 9.5.10 (security fixes)Jakub Jirutka2017-11-211-5/+8
| | | | | | | | Fixes: CVE-2017-15098, CVE-2017-15099 Release Notes: https://www.postgresql.org/about/news/1801/ PostgreSQL on Alpine has never been affected by CVE-2017-12172.
* main/openssl: security upgrade to 1.0.2mAndy Postnikov2017-11-091-4/+7
| | | | | | | CVE-2017-3735 CVE-2017-3736 fixes #8116
* main/roundcubemail: security upgrade to 1.2.7 (CVE-2017-16651)Leonardo Arena2017-11-091-5/+7
|
* main/xen: add secinfoLeonardo Arena2017-10-251-0/+13
|
* main/xen: security upgrade to 4.6.6Leonardo Arena2017-10-2543-3346/+461
| | | | | | (CVE-2017-12135, CVE-2017-12137, CVE-2017-12136, CVE-2017-12134, CVE-2017-12855) fixes #7734
* main/xen: update sourceLeonardo Arena2017-10-251-2/+2
|
* main/xen: security fixesLeonardo Arena2017-10-255-1/+390
| | | | | | (CVE-2017-14316, CVE-2017-14317, CVE-2017-14318, CVE-2017-14319) fixes #7822
* main/gdk-pixbuf: security fix (CVE-2017-2862)Leonardo Arena2017-10-252-4/+55
| | | | fixes #7868
* main/newsbeuter: security fix (CVE-2017-14500)Leonardo Arena2017-10-242-5/+51
| | | | fixes #7879
* main/curl: security fix for CVE-2017-1000257Natanael Copa2017-10-242-4/+47
| | | | fixes #8041
* main/samba: security upgrade to 4.4.16Leonardo Arena2017-10-242-54/+12
| | | | | | (CVE-2017-12150, CVE-2017-12151, CVE-2017-12163) fixes #7894