Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/spl-vanilla: rebuild against kernel 4.4.44-r0 | Natanael Copa | 2017-01-23 | 1 | -1/+1 | |
| | ||||||
* | main/linux-vanilla: upgrade to 4.4.44 | Natanael Copa | 2017-01-23 | 1 | -4/+4 | |
| | ||||||
* | main/php5: upgrade to 5.6.30 (security fixes) | Andy Postnikov | 2017-01-20 | 1 | -5/+5 | |
| | | | | Security release http://php.net/archive/2017.php#id2017-01-19-3 | |||||
* | community/php7: upgrade to 7.0.15 (security fixes) | Andy Postnikov | 2017-01-19 | 1 | -5/+5 | |
| | ||||||
* | main/irssi: security upgrade to 0.8.21 - fixes #6691 | Sergei Lukin | 2017-01-18 | 1 | -5/+6 | |
| | | | | | | | | CVE-2017-5193: A NULL pointer dereference in the nickcmp function. CVE-2017-5194: Use after free when receiving invalid nick message. CVE-2017-5356: Out of bounds read when Printing the value. CVE-2017-5195: Out of bounds read in certain incomplete control codes. CVE-2017-5196: Out of bounds read in certain incomplete character sequences. | |||||
* | main/gtest: added missing dir in -dev package. Fixes #6685 | Francesco Colista | 2017-01-17 | 1 | -16/+8 | |
| | ||||||
* | community/nodejs-current: add depends ca-certificates | Jakub Jirutka | 2017-01-14 | 1 | -1/+2 | |
| | ||||||
* | main/nodejs: add depends ca-certificates | Jakub Jirutka | 2017-01-14 | 1 | -1/+2 | |
| | ||||||
* | main/bind: security upgrade to 9.10.4_p5 - fixes #6676 | Sergei Lukin | 2017-01-13 | 1 | -8/+15 | |
| | | | | | | CVE-2016-9131: A malformed response to an ANY query can cause an assertion failure during recursion CVE-2016-9147: An error handling a query response containing inconsistent DNSSEC information could cause an assertion failure CVE-2016-9444: An unusually-formed DS record response could cause an assertion failure | |||||
* | community/docker: security upgrade to 1.12.6 (CVE-2016-9962) | Natanael Copa | 2017-01-12 | 1 | -4/+4 | |
| | | | | fixes #6672 | |||||
* | main/php5-phpmailer: security fixes #6623 | Sergey Lukin | 2017-01-12 | 2 | -6/+87 | |
| | | | | | | | | | | | | | | | CVE-2016-10033 CVE-2016-10045 Issues were fixed in 5.2.18 and 5.2.20 However, there were major changes between 5.2.4 and 5.2.20 https://github.com/PHPMailer/PHPMailer/blob/master/changelog.md This upgrade contains patch which is based on 2 commits containing fix for CVE-2016-10045 and CVE-2016-10033: https://github.com/PHPMailer/PHPMailer/commit/9743ff5c7ee16e8d49187bd2e11149afb9485eae https://github.com/PHPMailer/PHPMailer/commit/833c35fe39715c3d01934508987e97af1fbc1ba0 Commits were adjusted to 5.2.4 | |||||
* | main/libvncserver: security fixes #6638 | Sergey Lukin | 2017-01-12 | 3 | -8/+128 | |
| | | | | | CVE-2016-9941: Heap-based buffer overflow in rfbproto.c CVE-2016-9942: Heap-based buffer overflow in ultra.c | |||||
* | main/freeradius: fix circular dep | Natanael Copa | 2017-01-11 | 1 | -2/+3 | |
| | | | | move the radeapclient to the -eap subpackage | |||||
* | community/quassel: fix circular dep | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/mkinitfs: upgrade to 3.0.9 | Natanael Copa | 2017-01-11 | 2 | -29/+5 | |
| | ||||||
* | main/qemu: enable ncurses again | Natanael Copa | 2017-01-11 | 2 | -1/+19 | |
| | | | | (cherry picked from commit 2aa1d10d4130b7e0a967f9ace1972be1994ff7a6) | |||||
* | main/zfs-vanilla: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/spl-vanilla: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/linux-vanilla: upgrade to 4.4.41 | Natanael Copa | 2017-01-11 | 1 | -5/+5 | |
| | ||||||
* | main/linux-vanilla: add sdhci-acpi module | Natanael Copa | 2017-01-11 | 3 | -9/+9 | |
| | ||||||
* | main/zfs-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/xtables-addons-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/spl-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/open-vm-tools-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/ipfw-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/drbd9-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/devicemaster-linux-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/dahdi-linux-grsec: rebuild against kernel 4.4.41-r0 | Natanael Copa | 2017-01-11 | 1 | -2/+2 | |
| | ||||||
* | main/linux-grsec: upgrade to 4.4.41 | Natanael Copa | 2017-01-11 | 1 | -8/+8 | |
| | ||||||
* | main/linux-grsec: fix linux-virtgrsec-dev | Natanael Copa | 2017-01-11 | 1 | -11/+3 | |
| | ||||||
* | main/linux-grsec: Add sdhci-acpi module | Nicolas Porcel | 2017-01-11 | 3 | -9/+9 | |
| | ||||||
* | community/firejail: update to 0.9.44.4 | Stuart Cardall | 2017-01-11 | 1 | -4/+4 | |
| | | | | | | | | | | | firejail (0.9.44.4) baseline; urgency=low * security: --bandwidth root shell found by Martin Carpenter (CVE-2017-5207) * security: disabled --allow-debuggers when running on kernel versions prior to 4.8; a kernel bug in ptrace system call allows a full bypass of seccomp filter; problem reported by Lizzie Dixon (CVE-2017-5206) * security: root exploit found by Sebastian Krahmer (CVE-2017-5180) -- netblue30 Sat, 7 Jan 2017 10:00:00 -0500 | |||||
* | main/aconf: upgrade to 0.6.5 | Kaarle Ritvanen | 2017-01-09 | 1 | -4/+4 | |
| | ||||||
* | community/ruby2.1: fix error on libressl | Jakub Jirutka | 2017-01-06 | 2 | -5/+49 | |
| | ||||||
* | main/openssh: remove url from secfixes comment | Natanael Copa | 2017-01-06 | 1 | -2/+1 | |
| | ||||||
* | main/icu: fix typo in secfixes comment | Natanael Copa | 2017-01-06 | 1 | -1/+1 | |
| | ||||||
* | testing/acme-client: move to community | ScrumpyJack | 2017-01-06 | 2 | -0/+0 | |
| | | | | | | Successful testing over 3 months and 2 version, move to community. (cherry picked from commit 0b40d7adc34ad5f218876e5496de342698fd3f25) | |||||
* | main/pcsc-lite: security upgrade to 1.8.20 (CVE-2016-10109) | Timo Teräs | 2017-01-06 | 2 | -31/+10 | |
| | | | | | fixes #6629 remove unneeded patch (upstream fixed issue) | |||||
* | main/ssh-getkey-ldap: upgrade to 0.1.2 | Jakub Jirutka | 2017-01-04 | 1 | -4/+4 | |
| | ||||||
* | main/open-vm-tools: fix the strerror_r patch | Natanael Copa | 2017-01-04 | 2 | -6/+19 | |
| | | | | fixes #5487 | |||||
* | main/open-vm-tools: enable -dbg | Natanael Copa | 2017-01-02 | 1 | -2/+2 | |
| | ||||||
* | main/open-vm-tools: fix segfault in error reporting | Natanael Copa | 2017-01-02 | 2 | -1/+25 | |
| | | | | fixes #5487 | |||||
* | community/phpmyadmin: mistake fixed in secfixes info | Sergey Lukin | 2016-12-30 | 1 | -2/+1 | |
| | ||||||
* | community/phpmyadmin: security upgrade to 4.6.5.2 - fixes #6595 | Sergey Lukin | 2016-12-29 | 1 | -4/+28 | |
| | | | | | | | | | | | | | | | | | | | | | | | CVE-2016-9847: Unsafe generation of blowfish secret CVE-2016-9848: phpinfo information leak value of sensitive (HttpOnly) cookies CVE-2016-9849: Username deny rules bypass (AllowRoot & Others) by using Null Byte CVE-2016-9850: Username rule matching issues CVE-2016-9851: With a crafted request parameter value it is possible to bypass the logout timeout. CVE-2016-9852 CVE-2016-9853 CVE-2016-9854 CVE-2016-9855: Multiple full path disclosure vulnerabilities CVE-2016-9856 CVE-2016-9857: Multiple XSS vulnerabilities CVE-2016-9858 CVE-2016-9859 CVE-2016-9860: We consider these vulnerabilities to be of moderate severity. CVE-2016-9861: Bypass white-list protection for URL redirection CVE-2016-9862: BBCode injection vulnerability CVE-2016-9863: DOS vulnerability in table partitioning CVE-2016-9864: Multiple SQL injection vulnerabilities CVE-2016-9865: Incorrect serialized string parsing CVE-2016-9866: CSRF token not stripped from the URL Jumping through 3 versions: 4.6.5, 4.6.5.1, 4.6.5.2 These upgrades does not contain major changes: https://www.phpmyadmin.net/news/2016/11/25/phpmyadmin-401018-44159-and-465-are-released/ https://www.phpmyadmin.net/news/2016/11/26/phpmyadmin-4651-released/ https://www.phpmyadmin.net/news/2016/12/5/phpmyadmin-4652-released/ | |||||
* | main/openssh: track secfixes | Sergey Lukin | 2016-12-29 | 1 | -0/+9 | |
| | ||||||
* | community/imapsync: fix depends for alpine 3.5 | Stuart Cardall | 2016-12-29 | 1 | -2/+2 | |
| | | | | fixes depends: perl-test-tester ==> perl-test-simple | |||||
* | main/aconf: upgrade to 0.6.3 | Kaarle Ritvanen | 2016-12-28 | 1 | -4/+4 | |
| | ||||||
* | main/ldoc: upgrade to 1.4.6 | Kaarle Ritvanen | 2016-12-28 | 1 | -4/+4 | |
| | ||||||
* | main/icu: APKBUILD track secfixes | Leonardo Arena | 2016-12-27 | 1 | -0/+2 | |
| | ||||||
* | main/icu: security fix (CVE-2016-7415). Fixes #6548 | Leonardo Arena | 2016-12-27 | 2 | -4/+186 | |
| | | | | (cherry picked from commit 1fa78865839b8c66006d1ae3a0a626e7acc7787d) |