Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/net-snmp: security fix CVE-2012-6151 | Leonardo Arena | 2014-03-04 | 2 | -2/+194 | |
| | ||||||
* | main/elinks: security fix. Fixes #2665 | Leonardo Arena | 2014-03-04 | 2 | -3/+101 | |
| | ||||||
* | main/freeradius: upgrade to 2.2.3. Fix CVE-2014-2015. Backports enhancements ↵ | Leonardo Arena | 2014-03-04 | 4 | -64/+165 | |
| | | | | and fixes from 2.7-stable. Fixes #2720 | |||||
* | main/zabbix: security upgrade to 2.0.11 (CVE-2014-1685, CVE-2014-1682, ↵ | Leonardo Arena | 2014-03-03 | 3 | -42/+51 | |
| | | | | | | | | | | CVE-2013-5572) (cherry picked from commit 870d04b5a1a7a9fca5bb0db44e923d8cd71e0fe5) Conflicts: main/zabbix/APKBUILD main/zabbix/automake.patch | |||||
* | main/augeas: security fix for CVE-2012-0786 and CVE-2012-0787 | Natanael Copa | 2014-03-03 | 3 | -3/+987 | |
| | | | | fixes #2668 | |||||
* | main/nss: security upgrade to 3.15.4 (CVE-2013-1740) | Natanael Copa | 2014-03-03 | 6 | -213/+42 | |
| | | | | | fixes #2645 fixes #2573 | |||||
* | main/nspr: upgrade to 4.10.3 | Natanael Copa | 2014-03-03 | 4 | -101/+5 | |
| | ||||||
* | main/pidgin: security upgrade to 2.10.9 (various CVEs) | Natanael Copa | 2014-03-03 | 1 | -2/+2 | |
| | | | | | | | | | | | | | | | | | | | | | fixes #2679 CVE-2014-0020 Remotely triggerable crash in IRC argument parsing CVE-2013-6490 Buffer overflow in SIMPLE header parsing CVE-2013-6489 Buffer overflow in MXit emoticon parsing CVE-2013-6487 Buffer overflow in Gadu-Gadu HTTP parsing CVE-2013-6486 Pidgin uses clickable links to untrusted executables CVE-2013-6485 Buffer overflow parsing chunked HTTP responses CVE-2013-6484 Crash reading response from STUN server CVE-2013-6483 XMPP doesn't verify 'from' on some iq replies CVE-2013-6482 NULL pointer dereference parsing SOAP data in MSN CVE-2013-6482 NULL pointer dereference parsing OIM data in MSN CVE-2013-6482 NULL pointer dereference parsing headers in MSN CVE-2013-6481 Remote crash reading Yahoo! P2P message CVE-2013-6479 Remote crash parsing HTTP responses CVE-2013-6478 Crash when hovering pointer over a long URL CVE-2013-6477 Crash handling bad XMPP timestamp CVE-2012-6152 Yahoo! remote crash from incorrect character encoding | |||||
* | main/file: security upgrade to 5.17 (CVE-2014-1943) | Natanael Copa | 2014-03-03 | 1 | -2/+2 | |
| | | | | fixes #2693 | |||||
* | main/libpng: security fix for CVE-2013-6954 | Natanael Copa | 2014-02-25 | 2 | -2/+44 | |
| | | | | fixes #2698 | |||||
* | main/ffmpeg: upgrade to 1.0.4 | Natanael Copa | 2014-02-25 | 1 | -3/+3 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes #2703 1.0.4 Fixes following vulnerabilities: CVE-2013-0866 CVE-2013-0865 CVE-2013-0863 CVE-2013-0861 CVE-2013-0860 CVE-2013-0858 CVE-2013-0845 CVE-2013-0844 CVE-2013-0868 CVE-2013-0862 1.0.2 Fixes following vulnerabilities: CVE-2012-6617 CVE-2012-6618 1.0.1 Fixes following vulnerabilities: CVE-2013-0859 CVE-2013-0857 CVE-2013-0856 CVE-2013-0855 CVE-2013-0853 CVE-2013-0852 CVE-2013-0851 CVE-2013-0850 CVE-2013-0849 CVE-2013-0848 CVE-2013-0846 | |||||
* | main/python: security fix for CVE-2014-1912 | Natanael Copa | 2014-02-24 | 2 | -4/+21 | |
| | | | | fixes #2711 | |||||
* | main/curl: fix CVE-2014-0015 | Natanael Copa | 2014-02-04 | 2 | -3/+53 | |
| | | | | fixes #2673 | |||||
* | main/bind: security upgrade to 9.9.4_p2 (CVE-2014-0591) | Natanael Copa | 2014-01-15 | 1 | -2/+2 | |
| | | | | fixes #2606 | |||||
* | main/links: security upgrade to 2.8 (CVE-2013-6050) | Natanael Copa | 2014-01-14 | 1 | -2/+2 | |
| | | | | fixes #2552 | |||||
* | main/spice: security fix for CVE-2013-4282 | Natanael Copa | 2014-01-14 | 2 | -1/+107 | |
| | | | | fixes #2596 | |||||
* | main/pixman: security fix for CVE-2013-6425 | Natanael Copa | 2014-01-14 | 2 | -5/+44 | |
| | ||||||
* | main/wireshark: security upgrade to 1.8.12 (CVE-2013-7112,CVE-2013-7114) | Natanael Copa | 2014-01-14 | 1 | -2/+2 | |
| | | | | fixes #2567 | |||||
* | main/openssl: security upgrade to 1.0.1f ↵ | Natanael Copa | 2014-01-14 | 2 | -47/+4 | |
| | | | | | | (CVE-2013-4353,CVE-2013-6449,CVE-2013-6450) fixes #2583 | |||||
* | main/libxfont: security upgrade to 1.4.7 (CVE-2013-6462) | Natanael Copa | 2014-01-14 | 1 | -2/+2 | |
| | | | | fixes #2587 | |||||
* | main/polkit: security fix for CVE-2013-4288 | Natanael Copa | 2013-12-24 | 2 | -2/+127 | |
| | | | | | ref #2471 fixes #2473 | |||||
* | main/xorg-server: security fix (CVE-2013-4396) | Natanael Copa | 2013-12-17 | 2 | -2/+80 | |
| | | | | fixes #2520 | |||||
* | main/php: security upgrade to 5.3.28 (CVE-2013-6420) | Natanael Copa | 2013-12-17 | 1 | -2/+2 | |
| | | | | fixes #2515 | |||||
* | main/mysql: security upgrade to 5.5.25 (CVE-2013-3783, CVE-2013-3793, ↵ | Leonardo Arena | 2013-12-17 | 1 | -2/+8 | |
| | | | | CVE-2013-3802, CVE-2013-3804, CVE-2013-3809, CVE-2013-3812, CVE-2013-3839, CVE-2013-5807). Fixes #2502 | |||||
* | main/vlc: security upgrade to 2.0.8 (CVE-2013-4388) | Natanael Copa | 2013-12-17 | 1 | -3/+3 | |
| | | | | fixes #2498 | |||||
* | main/openssl: don't use rdrand engine as default | Timo Teräs | 2013-12-17 | 2 | -2/+45 | |
| | | | | | | | | | | As security measure, do not rely solely on hardware random source. fixes #2510 (cherry picked from commit 1fd915b81678c58d35bf63761c260efd5362a93d) Conflicts: main/openssl/APKBUILD | |||||
* | main/asterisk: security upgrade to 11.6.1 | Timo Teräs | 2013-12-17 | 1 | -5/+8 | |
| | | | | | | | | | fixes #2505 AST-2013-004 Remote Crash From Late Arriving SIP ACK With SDP AST-2013-005 Remote Crash when Invalid SDP is sent in SIP Request AST-2013-006 Buffer Overflow when receiving odd length 16 bit SMS message AST-2013-007 Asterisk Manager User Dialplan Permission Escalation | |||||
* | main/gimp: security upgrade to 2.8.10 (CVE-2012-5576) | Natanael Copa | 2013-12-13 | 1 | -3/+3 | |
| | | | | fixes #2492 | |||||
* | main/varnish: security upgrade to 3.0.5 (CVE-2013-4484) | Natanael Copa | 2013-12-13 | 1 | -3/+3 | |
| | | | | fixes #2489 | |||||
* | main/samba: security upgrade to 3.6.22 (CVE-2013-4408,CVE-2012-6150) | Natanael Copa | 2013-12-10 | 1 | -2/+2 | |
| | | | | fixes #2483 | |||||
* | main/quagga: security fixes (CVE-2012-1820, CVE-2013-2236, CVE-2013-6051) | Natanael Copa | 2013-12-10 | 5 | -1/+284 | |
| | | | | | ref #2566 fixes #2468 | |||||
* | main/quagga: build fixes for automake and recent kernel headers | Natanael Copa | 2013-12-10 | 3 | -5/+39 | |
| | | | | (cherry picked from commit 62abf74f5e5e2c59a7a1e1612218cf5102fc28aa) | |||||
* | main/zabbix: security upgrade to 2.0.10 (CVE-2013-6824) | Leonardo Arena | 2013-12-09 | 2 | -2035/+8 | |
| | ||||||
* | main/alpine-conf: update download url and checksum | Natanael Copa | 2013-12-06 | 1 | -1/+1 | |
| | ||||||
* | main/alpine-conf: fix creating boot usb of v2.7 | Natanael Copa | 2013-12-06 | 2 | -8/+124 | |
| | | | | ref #2363 | |||||
* | main/perl-http-body: security fix CVE-2013-4407. Fixes #2458 | Leonardo Arena | 2013-12-03 | 2 | -2/+35 | |
| | ||||||
* | main/ruby: security upgrade to 1.9.3_p484 (CVE-2013-4164) | Natanael Copa | 2013-12-03 | 1 | -6/+2 | |
| | | | | fixes #2463 | |||||
* | main/memcached: security workaround for CVE-2011-4971 | Natanael Copa | 2013-12-03 | 2 | -1/+58 | |
| | | | | | ref #2451 fixes #2453 | |||||
* | main/nss: security upgrade to 3.14.5 (CVE-2013-1739). Fixes #2394 | Leonardo Arena | 2013-12-03 | 6 | -22/+204 | |
| | ||||||
* | main/poppler: security fix (CVE-2013-4473,CVE-2013-4474) | Natanael Copa | 2013-12-03 | 3 | -5/+110 | |
| | | | | fixes #2418 | |||||
* | main/xen: security fix for CVE-2013-4329/XSA-61 | Natanael Copa | 2013-12-03 | 2 | -1/+47 | |
| | | | | fixes #2423 | |||||
* | main/wireshark: security upgrade to 1.8.11 ↵ | Natanael Copa | 2013-11-26 | 1 | -2/+2 | |
| | | | | | | | (CVE-2013-5718,CVE-2013-5719,CVE-2013-5720,CVE-2013-5721,CVE-2013-5722,CVE-2013-4933,CVE-2013-6336,CVE-2013-6337,CVE-2013-6338,CVE-2013-6339,CVE-2013-6340) fixes #2425 fixes #2441 | |||||
* | main/gnupg: security upgrade to 2.0.22 (CVE-2013-4351) | Natanael Copa | 2013-11-26 | 1 | -2/+2 | |
| | | | | fixes #2430 | |||||
* | main/libgpg-error: upgrade to 1.11 | Natanael Copa | 2013-11-26 | 1 | -2/+4 | |
| | | | | | | | needed for gnupg-2.0.22 ref #2428 (cherry picked from commit d43a4f23e6aa55883c2b0b318a0596ae52a664f7) | |||||
* | main/curl: security upgrade to 7.33.0 (CVE-2013-4545) | Natanael Copa | 2013-11-25 | 2 | -63/+4 | |
| | | | | fixes #2378 | |||||
* | main/nginx: actually apply the patch for CVE-2013-4547 | Natanael Copa | 2013-11-20 | 2 | -5/+9 | |
| | ||||||
* | main/nginx: security fix (CVE-2013-4547) | Natanael Copa | 2013-11-20 | 2 | -10/+22 | |
| | | | | fixes #2369 | |||||
* | main/lighttpd: various sec fixes (CVE-2013-4508,CVE-2013-4559,CVE-2013-4560) | Natanael Copa | 2013-11-15 | 5 | -1/+428 | |
| | | | | | ref #2350 fixes #2352 | |||||
* | main/lighttpd: security upgrade to 1.4.33 (CVE-2012-5533) | Natanael Copa | 2013-11-15 | 2 | -27/+3 | |
| | ||||||
* | main/samba: security upgrade to 3.6.20 (CVE-2013-4475,CVE-2013-4476) | Natanael Copa | 2013-11-14 | 1 | -2/+2 | |
| | | | | fixes #2340 |