aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* main/apk-tools: upgrade to 2.7.5Timo Teräs2018-01-091-2/+2
|
* community/postgresql-bdr-extension0.9: downgrade to 0.9.0 to maintain ↵Leonardo Arena2018-01-081-2/+2
| | | | compatibility with earlier Alpine versions
* main/asterisk: upgrade to 14.7.5Timo Teräs2018-01-083-329/+90
| | | | | | | | | | | fixes #8354 AST-2017-009 Buffer overflow in pjproject header parsing can cause crash AST-2017-010 Buffer overflow in CDR's set user AST-2017-011 Memory leak in pjsip session resource AST-2017-012 Remote Crash Vulnerability in RTCP Stack AST-2017-013 DOS Vulnerability in Asterisk chan_skinny AST-2017-014 Crash in PJSIP resource when missing a contact header
* main/awstats: security fix (CVE-2017-1000501)Leonardo Arena2018-01-053-6/+149
| | | | Fixes #8373
* main/wget: security upgrade to 1.19.2 (CVE-2017-13089, CVE-2017-13090)Leonardo Arena2018-01-052-33/+8
| | | | Fixes #8074
* main/collectd: adjust security info tagLeonardo Arena2018-01-051-1/+1
|
* main/collectd: security fixes (CVE-2017-7401, CVE-2017-16820)Leonardo Arena2018-01-053-12/+120
| | | | Fixes #8170
* main/libxfont: security fix (CVE-2017-16611)Leonardo Arena2018-01-052-6/+113
| | | | Fixes #8224
* main/xen: security fixesLeonardo Arena2018-01-0524-2/+1902
| | | | | | | CVE-2017-15588, CVE-2017-15589, CVE-2017-15590, CVE-2017-15593, CVE-2017-15592, CVE-2017-15594, CVE-2017-15595, CVE-2017-15596, CVE-2017-15597, CVE-2017-17046 Fixes #8062
* main/wireshark: security upgrade to 2.2.11Leonardo Arena2017-12-291-2/+10
| | | | CVE-2017-17083, CVE-2017-17084, CVE-2017-17085
* main/xen: security fixes (CVE-2017-17044, CVE-2017-17045)Leonardo Arena2017-12-294-1/+369
| | | | Fixes #8220
* main/openssh: security fix (CVE-2017-15906)Leonardo Arena2017-12-292-3/+38
| | | | Fixes #8283
* main/heimdal: security fix (CVE-2017-17439)Leonardo Arena2017-12-292-2/+52
| | | | Fixes #8293
* main/rsync: security fixesLeonardo Arena2017-12-295-2/+149
| | | | | | CVE-2017-16548, CVE-2017-17433, CVE-2017-17434 Fixes #8319
* main/gd: security upgrade to 2.2.5 (CVE-2017-6362, CVE-2017-7890)Leonardo Arena2017-12-281-3/+8
| | | | Fixes #8329
* community/zabbix: upgrade to 3.2.11Leonardo Arena2017-12-281-2/+2
|
* main/ruby: security upgrade to 2.4.3Jakub Jirutka2017-12-151-2/+4
| | | | See: https://www.ruby-lang.org/en/news/2017/12/14/ruby-2-4-3-released/
* main/openssl: security upgrade to 1.0.2nColin Williams2017-12-151-2/+5
| | | | | | | | | fixes #8275 CVE-2017-3737 CVE-2017-3738 (cherry picked from commit d2d350f8a099c9ed303f00888e05626662e5c7f6)
* community/homer-api: apply LDAP security fixKaarle Ritvanen2017-12-142-4/+34
|
* community/graphicsmagick: security upgrade to 1.3.27.Francesco Colista2017-12-111-22/+13
| | | | | - Fixes #8096 - Fixes #7944 (last CVE was not fixed since the patch did not apply)
* main/bacula: fix rundirLeonardo Arena2017-12-084-5/+17
|
* main/redis: upgrade to 3.2.11Jakub Jirutka2017-12-071-2/+2
|
* main/samba: security upgrade to 4.6.11 (CVE-2017-14746,CVE-2017-15275)Natanael Copa2017-12-071-2/+2
| | | | fixes #8182
* main/tevent: upgrade to 0.9.34Natanael Copa2017-12-071-4/+2
|
* main/talloc: upgrade to 2.1.10Natanael Copa2017-12-071-2/+2
|
* main/ffmpeg: ssecurity upgrade to 3.2.9Natanael Copa2017-12-071-2/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixes #8206 3.2.9-r0: - CVE-2017-15186 3.2.8-r0: - CVE-2017-14054 - CVE-2017-14055 - CVE-2017-14056 - CVE-2017-14057 - CVE-2017-14058 - CVE-2017-14059 - CVE-2017-14169 - CVE-2017-14170 - CVE-2017-14171 - CVE-2017-14222 - CVE-2017-14223 - CVE-2017-14225 - CVE-2017-14767 3.2.7-r0: - CVE-2017-11399 - CVE-2017-11665 - CVE-2017-11665 - CVE-2017-11719 3.2.6-r0: - CVE-2017-9608 - CVE-2017-9993 3.2.5-r0: - CVE-2017-9991 - CVE-2017-9992 - CVE-2017-9994 - CVE-2017-9996 3.2.4-r0: - CVE-2017-5024 - CVE-2017-5025
* main/curl: security upgrade to 7.57.0Natanael Copa2017-12-071-2/+6
| | | | | | | | CVE-2017-8816 CVE-2017-8817 CVE-2017-8818 fixes #8213
* community/nextcloud: upgrade to 12.0.4Leonardo Arena2017-12-052-27/+3
|
* main/pcre: add secfixes comment for CVE-2017-16231Natanael Copa2017-12-041-0/+1
| | | | | | | | We are not affected by CVE-2017-16231 due to our build with --with-match-limit-recursion=8192. We had this option since first commit, version 7.8, and were never affected. fixes #8140
* main/nginx: fix upgrade from version < 1.12.0-r1Jakub Jirutka2017-11-242-2/+29
| | | | Fixes http://bugs.alpinelinux.org/issues/8057
* community/firefox-esr: security upgrade to 52.5.0Natanael Copa2017-11-231-2/+2
| | | | fixes #8058
* main/libvorbis: fix for CVE-2017-14160Natanael Copa2017-11-232-12/+70
| | | | | | upstream issue: https://gitlab.xiph.org/xiph/vorbis/issues/2330 fixes #7938
* main/quagga: security upgrade to 1.2.2 (CVE-2017-16227)Natanael Copa2017-11-231-3/+5
| | | | fixes #8083
* main/openvpn: security upgrade to 2.4.4 (CVE-2017-12166)Natanael Copa2017-11-231-2/+2
| | | | fixes #8126
* community/roundcubemail: fix secfixes commentNatanael Copa2017-11-231-2/+2
|
* main/busybox: secfixes for CVE-2017-15873,CVE-2017-16544Natanael Copa2017-11-233-1/+261
| | | | fixes #8188
* main/tiff: security upgrade to 4.0.9 (CVE-2017-16231,CVE-2017-16232)Natanael Copa2017-11-2319-1184/+5
| | | | fixes #8146
* main/postgresql: upgrade to 9.6.6 (security fixes)Jakub Jirutka2017-11-211-2/+5
| | | | | | | | Fixes: CVE-2017-15098, CVE-2017-15099 Release Notes: https://www.postgresql.org/about/news/1801/ PostgreSQL on Alpine has never been affected by CVE-2017-12172.
* main/varnish: security upgrade to 4.1.9 (CVE-2017-8807)Natanael Copa2017-11-213-154/+17
| | | | fixes #8165
* main/libvirt: security fix (CVE 2017-1000256). Fixes #8158Francesco Colista2017-11-212-2/+48
|
* community/docker-registry: security upgrade to 2.6.2Andy Postnikov2017-11-151-3/+3
| | | | CVE-2017-1146 https://github.com/docker/distribution/releases/tag/v2.6.2
* community/zabbix: upgrade to 3.2.10Leonardo Arena2017-11-091-2/+2
|
* main/openssl: security upgrade to 1.0.2mAndy Postnikov2017-11-091-2/+5
| | | | | | | | | CVE-2017-3735 CVE-2017-3736 fixes #8114 (cherry picked from commit c57b41c34309ede6b832e2edc306f6ab14a5d78c)
* main/openssl: upgrade to 1.0.2l, modernize aportTimo Teräs2017-11-091-31/+6
| | | | (cherry picked from commit da64f1dce381d98a8e06b16a19b5aea1d01170c4)
* community/roundcubemail: add secinfoLeonardo Arena2017-11-091-1/+3
|
* community/roundcubemail: security upgrade to 1.2.7 (CVE-2017-16651)Leonardo Arena2017-11-091-2/+2
|
* community/php5: upgrade to 5.6.32Kaarle Ritvanen2017-11-011-2/+2
| | | | (cherry picked from commit 21bbc56f76863fc86c1e72057371a9edaaf17e4e)
* main/lxc: add fixed patchJakub Jirutka2017-10-311-5/+5
|
* main/lxc: upgrade to 2.0.9 (bugfixes)Jakub Jirutka2017-10-313-85/+4
|
* community/lua-hiredis: modernize, compile all in build stepTimo Teräs2017-10-301-24/+14
|