Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/apk-tools: upgrade to 2.7.5 | Timo Teräs | 2018-01-09 | 1 | -2/+2 | |
| | ||||||
* | community/postgresql-bdr-extension0.9: downgrade to 0.9.0 to maintain ↵ | Leonardo Arena | 2018-01-08 | 1 | -2/+2 | |
| | | | | compatibility with earlier Alpine versions | |||||
* | main/asterisk: upgrade to 14.7.5 | Timo Teräs | 2018-01-08 | 3 | -329/+90 | |
| | | | | | | | | | | | fixes #8354 AST-2017-009 Buffer overflow in pjproject header parsing can cause crash AST-2017-010 Buffer overflow in CDR's set user AST-2017-011 Memory leak in pjsip session resource AST-2017-012 Remote Crash Vulnerability in RTCP Stack AST-2017-013 DOS Vulnerability in Asterisk chan_skinny AST-2017-014 Crash in PJSIP resource when missing a contact header | |||||
* | main/awstats: security fix (CVE-2017-1000501) | Leonardo Arena | 2018-01-05 | 3 | -6/+149 | |
| | | | | Fixes #8373 | |||||
* | main/wget: security upgrade to 1.19.2 (CVE-2017-13089, CVE-2017-13090) | Leonardo Arena | 2018-01-05 | 2 | -33/+8 | |
| | | | | Fixes #8074 | |||||
* | main/collectd: adjust security info tag | Leonardo Arena | 2018-01-05 | 1 | -1/+1 | |
| | ||||||
* | main/collectd: security fixes (CVE-2017-7401, CVE-2017-16820) | Leonardo Arena | 2018-01-05 | 3 | -12/+120 | |
| | | | | Fixes #8170 | |||||
* | main/libxfont: security fix (CVE-2017-16611) | Leonardo Arena | 2018-01-05 | 2 | -6/+113 | |
| | | | | Fixes #8224 | |||||
* | main/xen: security fixes | Leonardo Arena | 2018-01-05 | 24 | -2/+1902 | |
| | | | | | | | CVE-2017-15588, CVE-2017-15589, CVE-2017-15590, CVE-2017-15593, CVE-2017-15592, CVE-2017-15594, CVE-2017-15595, CVE-2017-15596, CVE-2017-15597, CVE-2017-17046 Fixes #8062 | |||||
* | main/wireshark: security upgrade to 2.2.11 | Leonardo Arena | 2017-12-29 | 1 | -2/+10 | |
| | | | | CVE-2017-17083, CVE-2017-17084, CVE-2017-17085 | |||||
* | main/xen: security fixes (CVE-2017-17044, CVE-2017-17045) | Leonardo Arena | 2017-12-29 | 4 | -1/+369 | |
| | | | | Fixes #8220 | |||||
* | main/openssh: security fix (CVE-2017-15906) | Leonardo Arena | 2017-12-29 | 2 | -3/+38 | |
| | | | | Fixes #8283 | |||||
* | main/heimdal: security fix (CVE-2017-17439) | Leonardo Arena | 2017-12-29 | 2 | -2/+52 | |
| | | | | Fixes #8293 | |||||
* | main/rsync: security fixes | Leonardo Arena | 2017-12-29 | 5 | -2/+149 | |
| | | | | | | CVE-2017-16548, CVE-2017-17433, CVE-2017-17434 Fixes #8319 | |||||
* | main/gd: security upgrade to 2.2.5 (CVE-2017-6362, CVE-2017-7890) | Leonardo Arena | 2017-12-28 | 1 | -3/+8 | |
| | | | | Fixes #8329 | |||||
* | community/zabbix: upgrade to 3.2.11 | Leonardo Arena | 2017-12-28 | 1 | -2/+2 | |
| | ||||||
* | main/ruby: security upgrade to 2.4.3 | Jakub Jirutka | 2017-12-15 | 1 | -2/+4 | |
| | | | | See: https://www.ruby-lang.org/en/news/2017/12/14/ruby-2-4-3-released/ | |||||
* | main/openssl: security upgrade to 1.0.2n | Colin Williams | 2017-12-15 | 1 | -2/+5 | |
| | | | | | | | | | fixes #8275 CVE-2017-3737 CVE-2017-3738 (cherry picked from commit d2d350f8a099c9ed303f00888e05626662e5c7f6) | |||||
* | community/homer-api: apply LDAP security fix | Kaarle Ritvanen | 2017-12-14 | 2 | -4/+34 | |
| | ||||||
* | community/graphicsmagick: security upgrade to 1.3.27. | Francesco Colista | 2017-12-11 | 1 | -22/+13 | |
| | | | | | - Fixes #8096 - Fixes #7944 (last CVE was not fixed since the patch did not apply) | |||||
* | main/bacula: fix rundir | Leonardo Arena | 2017-12-08 | 4 | -5/+17 | |
| | ||||||
* | main/redis: upgrade to 3.2.11 | Jakub Jirutka | 2017-12-07 | 1 | -2/+2 | |
| | ||||||
* | main/samba: security upgrade to 4.6.11 (CVE-2017-14746,CVE-2017-15275) | Natanael Copa | 2017-12-07 | 1 | -2/+2 | |
| | | | | fixes #8182 | |||||
* | main/tevent: upgrade to 0.9.34 | Natanael Copa | 2017-12-07 | 1 | -4/+2 | |
| | ||||||
* | main/talloc: upgrade to 2.1.10 | Natanael Copa | 2017-12-07 | 1 | -2/+2 | |
| | ||||||
* | main/ffmpeg: ssecurity upgrade to 3.2.9 | Natanael Copa | 2017-12-07 | 1 | -2/+31 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixes #8206 3.2.9-r0: - CVE-2017-15186 3.2.8-r0: - CVE-2017-14054 - CVE-2017-14055 - CVE-2017-14056 - CVE-2017-14057 - CVE-2017-14058 - CVE-2017-14059 - CVE-2017-14169 - CVE-2017-14170 - CVE-2017-14171 - CVE-2017-14222 - CVE-2017-14223 - CVE-2017-14225 - CVE-2017-14767 3.2.7-r0: - CVE-2017-11399 - CVE-2017-11665 - CVE-2017-11665 - CVE-2017-11719 3.2.6-r0: - CVE-2017-9608 - CVE-2017-9993 3.2.5-r0: - CVE-2017-9991 - CVE-2017-9992 - CVE-2017-9994 - CVE-2017-9996 3.2.4-r0: - CVE-2017-5024 - CVE-2017-5025 | |||||
* | main/curl: security upgrade to 7.57.0 | Natanael Copa | 2017-12-07 | 1 | -2/+6 | |
| | | | | | | | | CVE-2017-8816 CVE-2017-8817 CVE-2017-8818 fixes #8213 | |||||
* | community/nextcloud: upgrade to 12.0.4 | Leonardo Arena | 2017-12-05 | 2 | -27/+3 | |
| | ||||||
* | main/pcre: add secfixes comment for CVE-2017-16231 | Natanael Copa | 2017-12-04 | 1 | -0/+1 | |
| | | | | | | | | We are not affected by CVE-2017-16231 due to our build with --with-match-limit-recursion=8192. We had this option since first commit, version 7.8, and were never affected. fixes #8140 | |||||
* | main/nginx: fix upgrade from version < 1.12.0-r1 | Jakub Jirutka | 2017-11-24 | 2 | -2/+29 | |
| | | | | Fixes http://bugs.alpinelinux.org/issues/8057 | |||||
* | community/firefox-esr: security upgrade to 52.5.0 | Natanael Copa | 2017-11-23 | 1 | -2/+2 | |
| | | | | fixes #8058 | |||||
* | main/libvorbis: fix for CVE-2017-14160 | Natanael Copa | 2017-11-23 | 2 | -12/+70 | |
| | | | | | | upstream issue: https://gitlab.xiph.org/xiph/vorbis/issues/2330 fixes #7938 | |||||
* | main/quagga: security upgrade to 1.2.2 (CVE-2017-16227) | Natanael Copa | 2017-11-23 | 1 | -3/+5 | |
| | | | | fixes #8083 | |||||
* | main/openvpn: security upgrade to 2.4.4 (CVE-2017-12166) | Natanael Copa | 2017-11-23 | 1 | -2/+2 | |
| | | | | fixes #8126 | |||||
* | community/roundcubemail: fix secfixes comment | Natanael Copa | 2017-11-23 | 1 | -2/+2 | |
| | ||||||
* | main/busybox: secfixes for CVE-2017-15873,CVE-2017-16544 | Natanael Copa | 2017-11-23 | 3 | -1/+261 | |
| | | | | fixes #8188 | |||||
* | main/tiff: security upgrade to 4.0.9 (CVE-2017-16231,CVE-2017-16232) | Natanael Copa | 2017-11-23 | 19 | -1184/+5 | |
| | | | | fixes #8146 | |||||
* | main/postgresql: upgrade to 9.6.6 (security fixes) | Jakub Jirutka | 2017-11-21 | 1 | -2/+5 | |
| | | | | | | | | Fixes: CVE-2017-15098, CVE-2017-15099 Release Notes: https://www.postgresql.org/about/news/1801/ PostgreSQL on Alpine has never been affected by CVE-2017-12172. | |||||
* | main/varnish: security upgrade to 4.1.9 (CVE-2017-8807) | Natanael Copa | 2017-11-21 | 3 | -154/+17 | |
| | | | | fixes #8165 | |||||
* | main/libvirt: security fix (CVE 2017-1000256). Fixes #8158 | Francesco Colista | 2017-11-21 | 2 | -2/+48 | |
| | ||||||
* | community/docker-registry: security upgrade to 2.6.2 | Andy Postnikov | 2017-11-15 | 1 | -3/+3 | |
| | | | | CVE-2017-1146 https://github.com/docker/distribution/releases/tag/v2.6.2 | |||||
* | community/zabbix: upgrade to 3.2.10 | Leonardo Arena | 2017-11-09 | 1 | -2/+2 | |
| | ||||||
* | main/openssl: security upgrade to 1.0.2m | Andy Postnikov | 2017-11-09 | 1 | -2/+5 | |
| | | | | | | | | | CVE-2017-3735 CVE-2017-3736 fixes #8114 (cherry picked from commit c57b41c34309ede6b832e2edc306f6ab14a5d78c) | |||||
* | main/openssl: upgrade to 1.0.2l, modernize aport | Timo Teräs | 2017-11-09 | 1 | -31/+6 | |
| | | | | (cherry picked from commit da64f1dce381d98a8e06b16a19b5aea1d01170c4) | |||||
* | community/roundcubemail: add secinfo | Leonardo Arena | 2017-11-09 | 1 | -1/+3 | |
| | ||||||
* | community/roundcubemail: security upgrade to 1.2.7 (CVE-2017-16651) | Leonardo Arena | 2017-11-09 | 1 | -2/+2 | |
| | ||||||
* | community/php5: upgrade to 5.6.32 | Kaarle Ritvanen | 2017-11-01 | 1 | -2/+2 | |
| | | | | (cherry picked from commit 21bbc56f76863fc86c1e72057371a9edaaf17e4e) | |||||
* | main/lxc: add fixed patch | Jakub Jirutka | 2017-10-31 | 1 | -5/+5 | |
| | ||||||
* | main/lxc: upgrade to 2.0.9 (bugfixes) | Jakub Jirutka | 2017-10-31 | 3 | -85/+4 | |
| | ||||||
* | community/lua-hiredis: modernize, compile all in build step | Timo Teräs | 2017-10-30 | 1 | -24/+14 | |
| |