Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/xen: security fixes XSA 260-262 | Henrik Riomar | 2018-05-21 | 8 | -1/+1078 | |
| | | | | | | CVE-2018-8897 XSA-260 (depends x86-XPTI-reduce-.text.entry.patch) CVE-2018-10982 XSA-261 CVE-2018-10981 XSA-262 | |||||
* | main/sqlite: fix CVE-2018-8740 | Jakub Jirutka | 2018-05-20 | 2 | -1/+43 | |
| | | | | Ref #8786 (https://bugs.alpinelinux.org/issues/8786) | |||||
* | main/curl: security upgrade to 7.60.0 | prspkt | 2018-05-20 | 1 | -3/+6 | |
| | ||||||
* | community/lua-cqueues-pushy: upgrade to 20180221 snapshot | Timo Teräs | 2018-05-17 | 1 | -3/+3 | |
| | ||||||
* | community/stunnel: upgrade to 5.44 and enable SO_ORIGINAL_DST | Natanael Copa | 2018-05-15 | 1 | -3/+8 | |
| | | | | | Support for SO_ORIGINAL_DST will be silently disabled if linux-headers are missing at build time. | |||||
* | main/darkhttpd: Add svg support to default mimetypes | Carlo Landmeter | 2018-05-14 | 2 | -3/+33 | |
| | ||||||
* | community/zoneminder: add missing dependency | Kaarle Ritvanen | 2018-05-14 | 1 | -2/+2 | |
| | ||||||
* | main/postgresql: security upgrade to 10.4 | Jakub Jirutka | 2018-05-14 | 1 | -10/+12 | |
| | | | | | Fixes CVE-2018-1115 See https://www.postgresql.org/about/news/1851/ | |||||
* | main/wget: security upgrade to 1.19.5 | Andy Postnikov | 2018-05-10 | 1 | -3/+5 | |
| | ||||||
* | community/php7: security upgrade to 7.1.17 | Andy Postnikov | 2018-05-03 | 1 | -3/+7 | |
| | | | | CVE-2018-5712 | |||||
* | community/wireshark: security upgrade to 2.4.6 | Leonardo Arena | 2018-04-30 | 1 | -2/+13 | |
| | | | | | | | | CVE-2018-9256, CVE-2018-9257, CVE-2018-9258, CVE-2018-9260, CVE-2018-9261, CVE-2018-9262, CVE-2018-9263, CVE-2018-9264, CVE-2018-9267, CVE-2018-10194 Fixes #8822 | |||||
* | main/jq: security fix (CVE-2016-4074). Fixes #8808 | Leonardo Arena | 2018-04-30 | 2 | -3/+45 | |
| | ||||||
* | main/xen: security fixes | Henrik Riomar | 2018-04-30 | 3 | -1/+146 | |
| | | | | | CVE-2018-10472, XSA-258 CVE-2018-10471, XSA-259 | |||||
* | main/mkinitfs: virtio_net depends on virtio_pci | Carlo Landmeter | 2018-04-29 | 2 | -2/+27 | |
| | ||||||
* | main/mkinitfs: features add virtio_net to network modules | Carlo Landmeter | 2018-04-29 | 2 | -2/+25 | |
| | ||||||
* | community/php5: security upgrade to 5.6.36 | Andy Postnikov | 2018-04-28 | 1 | -2/+6 | |
| | | | | CVE-2018-5712 | |||||
* | community/drupal7: security upgrade to 7.59 | Andy Postnikov | 2018-04-28 | 1 | -2/+4 | |
| | | | | CVE-2018-7602 https://www.drupal.org/SA-CORE-2018-004 | |||||
* | community/firefox-esr: upgrade to 52.7.3 | Leonardo Arena | 2018-04-24 | 1 | -2/+2 | |
| | ||||||
* | community/nextcloud: upgrade to 12.0.6 | Jakub Jirutka | 2018-04-18 | 2 | -17/+2 | |
| | | | | Problem with iconv has been fixed in upstream: https://github.com/nextcloud/server/pull/8674. | |||||
* | main/perl: security upgrade to 5.26.2 | Leonardo Arena | 2018-04-17 | 1 | -7/+10 | |
| | | | | | | CVE-2018-6797, CVE-2018-6798, CVE-2018-6913 Fixes #8802 | |||||
* | community/roundcubemail: security upgrade to 1.3.6 (CVE-2018-9846) | Leonardo Arena | 2018-04-12 | 2 | -14/+28 | |
| | ||||||
* | main/clamav: security upgrade 0.99.4 | Leonardo Arena | 2018-04-11 | 2 | -28/+9 | |
| | | | | | | CVE-2018-0202, CVE-2018-1000085 Fixes #8694 | |||||
* | main/mariadb: security upgrade to 10.1.32 | Leonardo Arena | 2018-04-11 | 1 | -3/+13 | |
| | | | | | | | CVE-2017-10268, CVE-2017-10378, CVE-2017-15365, CVE-2018-2562 CVE-2018-2612, CVE-2018-2622, CVE-2018-2640, CVE-2018-2665, CVE-2018-2668 Fixes #8688 | |||||
* | community/zabbix: upgrade to 3.4.8 | Leonardo Arena | 2018-04-11 | 1 | -2/+2 | |
| | ||||||
* | community/php7: make zlib extension builtin | Andy Postnikov | 2018-04-05 | 1 | -4/+9 | |
| | | | | | | PHP lacks some functionality when zlib extension built dynamic. Ref #8299 (https://bugs.alpinelinux.org/issues/8299) | |||||
* | main/xen: upgrade to 4.9.2 | Henrik Riomar | 2018-04-05 | 17 | -2457/+5 | |
| | | | | | | | | Update musl-support.patch and remove hunk that fixes tools/libxl/libxl_arm_acpi.c as this is in upstream commit: 6b1a2704e7 libxl/arm: Fix build on arm64 + acpi Drop patches included in new upstream version | |||||
* | main/apk-tools: fix index refresh on time zero | Timo Teräs | 2018-04-05 | 2 | -2/+38 | |
| | | | | (cherry picked from commit 1dcf9e4a7be72e1b04fcfbdb24c4406e44bb1926) | |||||
* | community/firefox-esr: security upgrade to 52.7.2 | Natanael Copa | 2018-04-02 | 1 | -2/+2 | |
| | | | | | | | | | | | | | | fixes #8702 CVE-2018-5125: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 CVE-2018-5127: Buffer overflow manipulating SVG animatedPathSegList CVE-2018-5129: Out-of-bounds write with malformed IPC messages CVE-2018-5130: Mismatched RTP payload type can trigger memory corruption CVE-2018-5131: Fetch API improperly returns cached copies of no-store/no-cache resources CVE-2018-5144: Integer overflow during Unicode conversion CVE-2018-5145: Memory safety bugs fixed in Firefox ESR 52.7 | |||||
* | main/tiff: fix CVE-2018-5784 | prspkt | 2018-04-02 | 3 | -3/+135 | |
| | | | | fixes #8707 | |||||
* | main/openssl: security upgrade to 1.0.2o and rebuild depending pkgs | Andy Postnikov | 2018-04-01 | 4 | -5/+9 | |
| | | | | | | Fixes CVE-2017-3738, CVE-2018-0739, CVE-2018-0733 Rebuilds packages that link openssl statically. | |||||
* | main/zsh: fix CVE-2018-1071, CVE-2018-1083 | prspkt | 2018-03-31 | 3 | -2/+85 | |
| | ||||||
* | community/php7: security upgrade to 7.1.16 | Andy Postnikov | 2018-03-31 | 1 | -2/+2 | |
| | ||||||
* | community/php5: security upgrade to 5.6.35 | Andy Postnikov | 2018-03-31 | 1 | -2/+2 | |
| | ||||||
* | main/ruby: security upgrade to 2.4.4 | Natanael Copa | 2018-03-29 | 1 | -2/+9 | |
| | | | | | | | | | | | | | | | | | | | CVE-2017-17742: HTTP response splitting in WEBrick CVE-2018-6914: Unintentional file and directory creation with directory traversal in tempfile and tmpdir CVE-2018-8777: DoS by large request in WEBrick CVE-2018-8778: Buffer under-read in String#unpack CVE-2018-8779: Unintentional socket creation by poisoned NUL byte in UNIXServer and UNIXSocket CVE-2018-8780: Unintentional directory traversal by poisoned NUL byte in Dir fixes #8747 | |||||
* | community/go1.10: add backport | Natanael Copa | 2018-03-29 | 3 | -0/+279 | |
| | ||||||
* | community/drupal7: security upgrade to 7.58 | Andy Postnikov | 2018-03-28 | 1 | -2/+6 | |
| | | | | CVE-2018-7600 | |||||
* | community/icinga2: build fix | Natanael Copa | 2018-03-27 | 1 | -1/+1 | |
| | | | | use mariadb-dev instead of mariadb-connector-c | |||||
* | community/icinga2: security upgrade to 2.8.2 ↵ | Natanael Copa | 2018-03-27 | 1 | -3/+9 | |
| | | | | | | (CVE-2018-6532,CVE-2018-6534,CVE-2018-6535) fixes #8716 | |||||
* | main/uwsgi: security upgrade to 2.0.17 (CVE-2018-6758,CVE-2018-7490) | Natanael Copa | 2018-03-27 | 1 | -3/+5 | |
| | | | | fixes #8734 | |||||
* | main/apache2: security upgrade to 2.4.33 | Kaarle Ritvanen | 2018-03-27 | 1 | -3/+11 | |
| | | | | fixes #8729 | |||||
* | community/php5-apcu: upgrade to 5.1.11 | Andy Postnikov | 2018-03-26 | 1 | -5/+3 | |
| | | | | Fixes segfaults & random deadlock | |||||
* | community/rt4: fix email patch for v4.4.2 | Kory Prince | 2018-03-26 | 2 | -13/+49 | |
| | | | | Fixes #8712 | |||||
* | community/wireshark: security upgrade to 2.4.5 | Natanael Copa | 2018-03-26 | 1 | -2/+25 | |
| | | | | | | | | | | | CVE-2018-7320, CVE-2018-7321, CVE-2018-7322, CVE-2018-7323, CVE-2018-7324, CVE-2018-7325, CVE-2018-7326, CVE-2018-7327, CVE-2018-7328, CVE-2018-7329, CVE-2018-7330, CVE-2018-7331, CVE-2018-7332, CVE-2018-7333, CVE-2018-7334, CVE-2018-7335, CVE-2018-7336, CVE-2018-7337, CVE-2018-7417, CVE-2018-7418, CVE-2018-7419, CVE-2018-7420 Fixes #8651 | |||||
* | main/rsync: security upgrade to 3.1.3 (CVE-2018-5764) | Natanael Copa | 2018-03-20 | 5 | -144/+6 | |
| | | | | fixes #8676 | |||||
* | main/kamailio: version bump 5.0.6 | Nathan Angelacos | 2018-03-20 | 1 | -3/+3 | |
| | ||||||
* | main/curl: upgrade to 7.59.0 | prspkt | 2018-03-19 | 1 | -3/+7 | |
| | | | | fixes #8644 | |||||
* | main/samba: security upgrade to 4.7.6 | Jakub Jirutka | 2018-03-15 | 1 | -3/+6 | |
| | ||||||
* | Revert "main/nodejs: upgrade to 8.10.0" | Jakub Jirutka | 2018-03-15 | 1 | -2/+2 | |
| | | | | | | | | | | This reverts commit 0fec1f8393961c474ddc240c8f94f13c9002103f. It fails to build on v3.7 (but works on edge): ../src/node.cc: In function 'void node::SetupProcessObject(node::Environment*, int, const char* const*, int, const char* const*)': ../src/node.cc:3495:63: error: 'uv_os_getpid' was not declared in this scope Integer::New(env->isolate(), uv_os_getpid())); | |||||
* | main/nodejs: upgrade to 8.10.0 | Tim Brust | 2018-03-14 | 1 | -2/+2 | |
| | ||||||
* | main/ruby-bundler: upgrade to 1.16.1 | Jakub Jirutka | 2018-03-14 | 1 | -2/+2 | |
| |