aboutsummaryrefslogtreecommitdiffstats
path: root/main
Commit message (Collapse)AuthorAgeFilesLines
...
* main/libarchive: fix CVE-2020-19221 and CVE-2020-9308Leo2020-03-111-2/+6
|
* main/ppp: secfix for radius and EAPMilan P. Stanić2020-03-104-1/+149
| | | | | | | | | backported security fixes from upstream: radius: Prevent buffer overflow in rc_mksid() pppd: Fix bounds check in EAP code pppd: Ignore received EAP messages when not doing EAP add 'secfixes'
* main/py-django: security upgrade to 1.11.29Leo2020-03-101-2/+4
| | | | see #11288
* main/librsvg: security upgrade to 2.40.21Rasmus Thomsen2020-02-261-3/+7
|
* main/ncurses: move screen-256color to ncurses-terminfo-baseLeo2020-02-261-1/+2
|
* {main,community,testing}: make terminals depend on ncurses-terminfo-baseLeo2020-02-262-9/+5
|
* main/ncurses: re-arrange terminfo contentsLeo2020-02-261-6/+53
| | | | | | | | | | | | | | This re-arranges the contents of ncurses-terminfo-base so it contains all the terminfo entries for commonly used TERMs like xterm256-color. It also includes all terminfo entries for terminals we package like alacritty, gnome-terminal, konsole, kitty, st, etc. And a few others like putty, tmux and vte. The ncurses-terminfo-base packaged increased from 94.21 kB to 126.98 kB, a quite small increase when considering that now it is in the majority of cases the only package one has to install instead of having to rely on the massive ncurses-terminfo package.
* main/cvs: security upgrade to 1.12.12TBK2020-02-2516-53/+704
| | | | | | | | | Most distros uses 1.12.13 (https://repology.org/project/cvs/versions) but according to Gentoo it is usable, so following Gentoo (https://bugs.gentoo.org/124733) 1.12.12 is the way forward. CVEs: * CVE-2010-3846 - https://bugzilla.redhat.com/show_bug.cgi?id=642146 * CVE-2012-0804 - https://security-tracker.debian.org/tracker/CVE-2012-0804 * CVE-2017-12836 - https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871810#10
* main/putty: depend on ncurses-terminfoLeo2020-02-251-4/+2
|
* main/ncurses: fix automatic dependency due to symlinksLeo2020-02-251-10/+8
| | | | | | | | | | | | | | | | | | | | The -libs subpackage depended on ncurses-terminfo when it shouldn't because when moving $pkgdir/usr/lib also moved /usr/lib/terminfo which is a symlink to /usr/share/terminfo which is part of ncurses-terminfo and thus a dependency would be automatically added by the prepare_symlink() function from APKBUILD. So make the libs() function grab only actual libraries by matching /usr/lib/*.so.* (this does not match libraries meant for -dev which would be *.so) so /usr/lib/terminfo isn't caught up. Also make the terminfo() function move /usr/lib/terminfo to it. In the meantime also do other cleanup like removing unnecessary 'cd "$builddir"' declarations and make libs() depend on the same $pkgver-r$pkgrel of the ncurses-terminfo-base. fixes #11250
* main/faac: fix secfixesLeo2020-02-191-2/+2
|
* main/dmvpn: various fixesKaarle Ritvanen2020-02-186-3/+196
| | | | | | define ciphers for better security and performance close inactive SAs fix race conditions
* main/postgresql: security upgrade to 11.7J0WI2020-02-141-22/+24
|
* main/nodejs: security upgrade to 10.19.0Jakub Jirutka2020-02-071-3/+15
|
* main/openjpeg: secfixes (CVE-2020-6851,CVE-2020-8112)Natanael Copa2020-02-053-4/+83
| | | | | | fixes #11189 (cherry picked from commit a60544e51180dade6c8e710f1bfd7060618ede11)
* main/openjpeg: cleanup patches and update urlJ0WI2020-02-056-286/+2
| | | | (cherry picked from commit 18df15dbb366dab8b2d3261d3758f99b8524906d)
* main/openjpeg: fix path for cmakeprspkt2020-02-052-5/+17
| | | | (cherry picked from commit 1573948f7aaea2bda1ef5cbe9e8263f88658a028)
* main/sudo: fix CVE-2019-18634Jakub Jirutka2020-02-052-2/+101
|
* main/sudo: fix CVE-2019-14287Jakub Jirutka2020-02-052-2/+266
|
* main/py-django: security upgrade to 1.11.28Kaarle Ritvanen2020-02-041-2/+4
|
* main/samba: security upgrade to 4.10.12Leonardo Arena2020-01-271-2/+6
| | | | | | CVE-2019-14902, CVE-2019-14907, CVE-2019-19344 ref #11155
* main/freeradius: fix segfault in process request_running()Jakub Jirutka2020-01-262-2/+27
|
* main/alpine-conf: unbreak lbuNatanael Copa2020-01-242-2/+43
| | | | | | | fix regression in lbu that was introduced with commit commit 7ebf92cda21a (main/alpine-conf: fix lbu exit codes on error) ref https://gitlab.alpinelinux.org/alpine/alpine-conf/merge_requests/4
* ===== release 3.10.4 =====v3.10.4Natanael Copa2020-01-231-1/+1
|
* main/zfs-vanilla: rebuild against kernel 4.19.98-r0Natanael Copa2020-01-231-1/+1
|
* main/xtables-addons-vanilla: rebuild against kernel 4.19.98-r0Natanael Copa2020-01-231-1/+1
|
* main/drbd-vanilla: rebuild against kernel 4.19.98-r0Natanael Copa2020-01-231-1/+1
|
* main/devicemaster-linux-vanilla: rebuild against kernel 4.19.98-r0Natanael Copa2020-01-231-1/+1
|
* main/dahdi-linux-vanilla: rebuild against kernel 4.19.98-r0Natanael Copa2020-01-231-1/+1
|
* main/linux-vanilla: upgrade to 4.19.98Natanael Copa2020-01-231-2/+2
|
* main/linux-rpi: upgrade to 4.19.98Natanael Copa2020-01-231-3/+3
|
* main/linux-rpi: upgrade to 4.19.97Natanael Copa2020-01-231-3/+3
|
* main/zfs-vanilla: rebuild against kernel 4.19.97-r0Natanael Copa2020-01-221-1/+1
|
* main/xtables-addons-vanilla: rebuild against kernel 4.19.97-r0Natanael Copa2020-01-221-1/+1
|
* main/drbd-vanilla: rebuild against kernel 4.19.97-r0Natanael Copa2020-01-221-1/+1
|
* main/devicemaster-linux-vanilla: rebuild against kernel 4.19.97-r0Natanael Copa2020-01-221-1/+1
|
* main/dahdi-linux-vanilla: rebuild against kernel 4.19.97-r0Natanael Copa2020-01-221-1/+1
|
* main/linux-vanilla: upgrade to 4.19.97Natanael Copa2020-01-225-25/+30
|
* main/e2fsprogs: security upgrade to 1.45.5 (CVE-2019-5188)Natanael Copa2020-01-202-195/+5
| | | | fixes #11133
* main/ansible: security upgrade to 2.8.8 CVE-2019-14864 CVE-2019-14904 ↵Andy Postnikov2020-01-181-2/+6
| | | | CVE-2019-14905
* main/nginx: security fix (CVE-2019-20372)Leonardo Arena2020-01-172-1/+34
| | | | ref #11134
* main/xen: security upgrade to 4.12.2Leonardo Arena2020-01-151-56/+10
| | | | | | | | | | | CVE-2019-19579 XSA-306 CVE-2019-19582 XSA-307 CVE-2019-19583 XSA-308 CVE-2019-19578 XSA-309 CVE-2019-19580 XSA-310 CVE-2019-19577 XSA-311 ref #11132
* main/python2: security fix (CVE-2019-16935)Leonardo Arena2020-01-142-2/+96
| | | | ref #10872
* main/ulogd: fix logrotate patternKaarle Ritvanen2020-01-122-3/+3
| | | | exclude already rotated logs
* main/libjpeg-turbo: security upgrade to 2.0.4 (CVE-2019-2201)Natanael Copa2020-01-071-3/+3
| | | | fixes #10948
* main/hunspell: fix CVE-2019-16707Natanael Copa2020-01-072-3/+32
| | | | fixes #11101
* main/squid: add secinfoLeonardo Arena2019-12-311-0/+1
|
* main/squid: add secinfoLeonardo Arena2019-12-311-0/+1
|
* main/libxml2: security fix for CVE-2019-19956. Fixes #11098Francesco Colista2019-12-312-2/+39
|
* main/xen: security fixesLeonardo Arena2019-12-3127-1/+4799
| | | | | | | | | | | | - CVE-2019-18425 XSA-298 - CVE-2019-18421 XSA-299 - CVE-2019-18423 XSA-301 - CVE-2019-18424 XSA-302 - CVE-2019-18422 XSA-303 - CVE-2018-12207 XSA-304 - CVE-2019-11135 XSA-305 ref #10968