| Commit message (Collapse) | Author | Age | Files | Lines |
... | |
| |
|
| |
|
| |
|
|
|
|
|
| |
fixes #3678
ref https://github.com/alpinelinux/aports/pull/3678
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
S8165543: Better window framing
S8169026, CVE-2017-10274: Handle smartcard clean up better
S8169966: Larger AWT menus
S8170218: Improved Font Metrics
S8171252: Improve exception checking
S8171261: Stability fixes for lcms
S8174109, CVE-2017-10281: Better queuing priorities
S8174966, CVE-2017-10285: Unreferenced references
S8175940: More certificate subject checking
S8176751, CVE-2017-10295: Better URL connections
S8178794, CVE-2017-10388: Correct Kerberos ticket grants
S8180024: Improve construction of objects during deserialization
S8180711, CVE-2017-10346: Better invokespecial checks
S8181100, CVE-2017-10350: Better Base Exceptions
S8181323, CVE-2017-10347: Better timezone processing
S8181327, CVE-2017-10349: Better X processing
S8181370, CVE-2017-10345: Better keystore handling
S8181432, CVE-2017-10348: Better processing of unresolved permissions
S8181597, CVE-2017-10357: Process Proxy presentation
S8181612, CVE-2017-10355: More stable connection processing
S8181692, CVE-2017-10356: Update storage implementations
S8183028, CVE-2016-10165: Improve CMS header processing
S8184682, CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843: Upgrade compression library
ref #8018, #8111
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
fixes #7579
S8163958, CVE-2017-10102: Improved garbage collection
S8167228: Update to libpng 1.6.28
S8169209, CVE-2017-10053: Improved image post-processing steps
S8169392, CVE-2017-10067: Additional jar validation steps
S8170966, CVE-2017-10081: Right parenthesis issue
S8171539, CVE-2017-10078: Better script accessibility for JavaScript
S8172204, CVE-2017-10087: Better Thread Pool execution
S8172461, CVE-2017-10089: Service Registration Lifecycle
S8172465, CVE-2017-10090: Better handling of channel groups
S8172469, CVE-2017-10096: Transform Transformer Exceptions
S8173286, CVE-2017-10101: Better reading of text catalogs
S8173697, CVE-2017-10107: Less Active Activations
S8173770, CVE-2017-10074: Image conversion improvements
S8174098, CVE-2017-10110: Better image fetching
S8174105, CVE-2017-10108: Better naming attribution
S8174113, CVE-2017-10109: Better sourcing of code
S8174770: Check registry registration location
S8174873: Improved certificate procesing
S8175106, CVE-2017-10115: Higher quality DSA operations
S8175110, CVE-2017-10118: Higher quality ECDSA operations
S8176055: JMX diagnostic improvements
S8176067, CVE-2017-10116: Proper directory lookup processing
S8176760, CVE-2017-10135: Better handling of PKCS8 material
S8178135, CVE-2017-10176: Additional elliptic curve support
S8179101, CVE-2017-10193: Improve algorithm constraints implementation
S8179998, CVE-2017-10198: Clear certificate chain connections
S8181420, CVE-2017-10074: PPC: Image conversion improvements
S8183551, CVE-2017-10074, PR3423: AArch64: Image conversion improvements
S8184185, CVE-2017-10111: Rearrange MethodHandle arrangements
|
|
|
|
| |
Fixes #8995
|
|
|
|
| |
Fixes #8989
|
|
|
|
|
|
| |
CVE-2018-6797, CVE-2018-6798, CVE-2018-6913
Fixes #8803
|
|
|
|
| |
Fixes #8831
|
|
|
|
|
|
|
|
| |
CVE-2018-10472 XSA-258
CVE-2018-10471 XSA-259
CVE-2018-8897 XSA-260 (depends on 4-patches from stable-4.8)
CVE-2018-10982 XSA-261
CVE-2018-10981 XSA-262
|
|
|
|
|
|
|
|
|
|
|
| |
fixes for:
-CVE-2018-10536
-CVE-2018-10537
-CVE-2018-10538
-CVE-2018-10539
-CVE-2018-10540
Fixes #8913
|
|
|
|
|
|
| |
CVE-2018-6767, CVE-2018-7253, CVE-2018-7254
Fixes #8594
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
CVE-2018-11356, CVE-2018-11357, CVE-2018-11358
CVE-2018-11359, CVE-2018-11360, CVE-2018-11362
Additional secfixes from earlier releases after 2.2.12:
CVE-2018-7320, CVE-2018-7321, CVE-2018-7322, CVE-2018-7323, CVE-2018-7324,
CVE-2018-7325, CVE-2018-7326, CVE-2018-7327, CVE-2018-7328, CVE-2018-7329,
CVE-2018-7330, CVE-2018-7331, CVE-2018-7332, CVE-2018-7333, CVE-2018-7334,
CVE-2018-7335, CVE-2018-7336, CVE-2018-7417, CVE-2018-7418, CVE-2018-7419,
CVE-2018-7420
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Security fiexes for the following CVEs:
CVE-2017-2887
CVE-2017-12122
CVE-2017-14440
CVE-2017-14441
CVE-2017-14442
CVE-2017-14448
CVE-2017-14450
CVE-2018-3837
CVE-2018-3838
CVE-2018-3839
|
|
|
|
| |
fixes #8968
|
|
|
|
| |
fixes #8948
|
|
|
|
|
|
|
|
|
|
| |
This fixes clang testsuite.
Patch was taken from upstream binutils-2_30-branch
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=shortlog;h=refs/heads/binutils-2_30-branch
Upstream report:
https://sourceware.org/ml/binutils/2018-03/msg00183.html
|
|
|
|
|
| |
fixes #7315
fixes #8881
|
|
|
|
|
|
| |
* Remove hash-style-gnu.patch in favor of the patch adding a configure flag for it from upstream
* Add gold-mips.patch from Debian, which makes gold configure correctly for MIPS64 targets
* Use CTARGET_ARCH instead of CARCH to correctly determine whether to enable the x86_64-pep target or not
|
| |
|
|
|
|
|
|
| |
fixes #8939
This reverts commit 1fae29db4daf9eb7f4e39aab7ce3bd37d18cc74e.
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
fix busybox wget https support by using an external ssl_client helper
for https.
Disable the use of external openssl. This was fixed to check
certificates as a temporary solution. openssl can not produce any useful
error messages on certificate errors. It is big. So we simply disable
its use.
We auto-install ssl_client if both libssl and busybox are installed. This
is to keep backwards compatibility.
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
| |
Fixes CVE-2018-1115
See https://www.postgresql.org/about/news/1851/
|
| |
|
|
|
|
| |
CVE-2018-5712
|
| |
|
|
|
|
| |
CVE-2018-5712
|
|
|
|
| |
CVE-2018-7602 https://www.drupal.org/SA-CORE-2018-004
|
| |
|
|
|
|
|
|
| |
CVE-2018-0202, CVE-2018-1000085
Fixes #8695
|
|
|
|
|
|
|
| |
CVE-2017-10268, CVE-2017-10378, CVE-2017-15365, CVE-2018-2562
CVE-2018-2612, CVE-2018-2622, CVE-2018-2640, CVE-2018-2665, CVE-2018-2668
Fixes #8689
|
| |
|
|
|
|
| |
fixes #8702
|
|
|
|
|
|
| |
Fixes CVE-2017-3738, CVE-2018-0739, CVE-2018-0733
Rebuilds packages that link openssl statically.
|
| |
|
| |
|