Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | main/perl: security upgrade to 5.24.3 (CVE-2017-12837,CVE-2017-12883) | Natanael Copa | 2017-10-10 | 1 | -4/+9 | |
| | | | | fixes #7899 | |||||
* | main/curl: security upgrade to 7.56.0 (CVE-2017-1000254) | Natanael Copa | 2017-10-04 | 2 | -40/+4 | |
| | | | | fixes #7963 | |||||
* | main/busybox: add secfix comment for CVE-2016-6301 | Natanael Copa | 2017-10-03 | 1 | -0/+4 | |
| | | | | so it gets whitelisted | |||||
* | main/python3: split out wininst*.exe | Natanael Copa | 2017-10-03 | 1 | -2/+9 | |
| | | | | | | | | the wininst is only needed for creating binary distribution for windows and is rarely needed. The precompiled .exe files contains statically linked version of zlib 1.2.8 which is vulnerable. Remove them from main package and save a couple of MB. | |||||
* | main/sqlite: security fix for CVE-2017-10989 | Natanael Copa | 2017-10-02 | 2 | -1/+24 | |
| | | | | fixes #7951 | |||||
* | main/dnsmasq: backport patches for CVE-2017-14491..14496 | Jakub Jirutka | 2017-10-02 | 8 | -9/+554 | |
| | ||||||
* | main/openjpeg: security upgrade to 2.2.0 and fixes | Francesco Colista | 2017-09-21 | 7 | -24/+309 | |
| | | | | | | | | | | | - CVE-2017-14040 - CVE-2017-14041 - CVE-2017-14151 - CVE-2017-14152 - CVE-2017-14164 Fixes partially #7827. Not yet fixed CVE-2017-14039 since patch is not available for 2.2.0 | |||||
* | main/apache2: fix CVE-2017-9798 aka Optionsbleed | Daniel Isaksen | 2017-09-21 | 2 | -1/+20 | |
| | ||||||
* | main/asterisk: security upgrade to 14.6.2 (CVE-2017-14099) | Timo Teräs | 2017-09-20 | 1 | -2/+2 | |
| | | | | AST-2017-008 (CVE-2017-14099): RTP/RTCP information leak | |||||
* | main/libgcrypt: security upgrade to 1.7.9 (CVE-2017-0378) | Natanael Copa | 2017-09-19 | 1 | -4/+8 | |
| | | | | fixes #7833 | |||||
* | main/bluez: security fixes for CVE-2017-1000250. Fixes #7845 | Francesco Colista | 2017-09-18 | 2 | -4/+37 | |
| | ||||||
* | main/tcpdump: upgrade to 4.9.2 | Andy Postnikov | 2017-09-15 | 1 | -4/+4 | |
| | | | | | Lots of security fixes http://www.tcpdump.org/tcpdump-changes.txt fixes #7840 | |||||
* | main/ruby: upgrade to 2.3.5 (security fixes) | Jakub Jirutka | 2017-09-15 | 1 | -4/+14 | |
| | ||||||
* | main/acf-lib: upgrade to 0.10.1 | Ted Trask | 2017-09-13 | 1 | -2/+2 | |
| | | | | (cherry picked from commit d04697c861eb21cdfe06baaee96d312586e03ee8) | |||||
* | main/acf-core: upgrade to 0.21.1 | Ted Trask | 2017-09-13 | 1 | -2/+2 | |
| | | | | (cherry picked from commit f2933db7a757a6207ed2f57cbb0de7c1aff265db) | |||||
* | main/libarchive: security fix for CVE-2017-14166. Fixes #7805 | Francesco Colista | 2017-09-11 | 2 | -8/+49 | |
| | ||||||
* | main/oniguruma: security upgrade to 6.3.0 | Francesco Colista | 2017-09-11 | 1 | -4/+4 | |
| | | | | | | | | | | | fixes #7813 CVE-2017-9224 CVE-2017-9225 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 CVE-2017-9229 | |||||
* | main/asterisk: security upgrade to 14.6.1 | Timo Teräs | 2017-09-06 | 3 | -151/+357 | |
| | | | | | | | | fixes #7791 AST-2017-005: Media takeover in RTP stack AST-2017-006: Shell access command injection in app_minivm AST-2017-007: Remote Crash Vulerability in res_pjsip | |||||
* | main/libraw: security fixes from debian | Timo Teräs | 2017-09-05 | 2 | -7/+96 | |
| | | | | | | | fixes #7742 CVE-2017-6886 CVE-2017-6887 | |||||
* | main/postgresql: upgrade to 9.6.5 | Jakub Jirutka | 2017-09-05 | 1 | -15/+3 | |
| | ||||||
* | main/libmspack: fix for CVE-2017-6419, CVE-2017-11423. Fixes #7758 | Francesco Colista | 2017-08-28 | 3 | -5/+117 | |
| | ||||||
* | main/openjpeg: fixed patch for CVE-2017-12982 | Francesco Colista | 2017-08-23 | 2 | -24/+14 | |
| | ||||||
* | main/openjpeg: security fix for CVE-2017-12982. Fixes #7714 | Francesco Colista | 2017-08-23 | 2 | -5/+36 | |
| | ||||||
* | main/nss: upgrade to 3.28.4 | Natanael Copa | 2017-08-22 | 1 | -5/+5 | |
| | | | | fixes #7305 | |||||
* | main/graphite2: security upgrade to 1.3.10 | Natanael Copa | 2017-08-22 | 1 | -4/+4 | |
| | | | | | | | CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777, CVE-2017-7778 fixes #7428 | |||||
* | main/newsbeuter: security fix for CVE-2017-12904 | Natanael Copa | 2017-08-22 | 2 | -4/+48 | |
| | | | | fixes #7728 | |||||
* | main/augeas: security fix for CVE-2017-7555 | Natanael Copa | 2017-08-22 | 2 | -1/+168 | |
| | | | | fixes #7721 | |||||
* | main/mariadb: security upgrade to 10.1.26 | Natanael Copa | 2017-08-22 | 2 | -7/+36 | |
| | | | | | | | | | | | | | | | fixes #7706 CVE-2017-3636 CVE-2017-3641 CVE-2017-3653 CVE-2017-3308 CVE-2017-3309 CVE-2017-3453 CVE-2017-3456 CVE-2017-3464 add temp patch for libressl-2.4 | |||||
* | main/mercurial: security upgrade to 4.3.1 | Natanael Copa | 2017-08-19 | 1 | -4/+8 | |
| | | | | | | | | fixes #7693 CVE-2017-9462 CVE-2017-1000115 CVE-2017-1000116 | |||||
* | main/jasper: fix secfixes comment | Natanael Copa | 2017-08-18 | 1 | -1/+1 | |
| | ||||||
* | main/lame: fix secfixes comment | Natanael Copa | 2017-08-18 | 1 | -1/+1 | |
| | ||||||
* | main/supervisor: security upgrade to 3.2.4 (CVE-2017-11610). Fixes #7687 | Francesco Colista | 2017-08-17 | 1 | -5/+10 | |
| | ||||||
* | main/c-ares: fix for CVE-2017-1000381. Fixes #7527 | Francesco Colista | 2017-08-14 | 2 | -5/+52 | |
| | ||||||
* | main/postgresql: security upgrade to 9.6.4 ↵ | Natanael Copa | 2017-08-14 | 1 | -4/+8 | |
| | | | | | | (CVE-2017-7546,CVE-2017-7547,CVE-2017-7548) fixes #7662 | |||||
* | main/subversion: security upgrade to 1.9.7. Fixes #7669 | Francesco Colista | 2017-08-14 | 1 | -4/+9 | |
| | ||||||
* | main/libsoup: security upgrade to 2.56.1 | Francesco Colista | 2017-08-14 | 2 | -4/+65 | |
| | | | | | | CVE-2017-2885 Fixes #7678 | |||||
* | main/curl: security upgrade to 7.55.0 | Natanael Copa | 2017-08-14 | 5 | -437/+45 | |
| | | | | | | | | CVE-2017-1000099 CVE-2017-1000100 CVE-2017-1000101 fixes #7655 | |||||
* | main/git: update to 2.11.3 (CVE-2017-1000117) | Shiz | 2017-08-11 | 1 | -4/+8 | |
| | ||||||
* | main/heimdal: fix for CVE-2017-11103. Fixes #7540 | Francesco Colista | 2017-08-09 | 2 | -4/+44 | |
| | ||||||
* | main/samba: fix for CVE-2017-11103. Fixes #7534 | Francesco Colista | 2017-08-09 | 2 | -2/+66 | |
| | ||||||
* | main/memcached: fix for CVE-2017-9951. Fixes #7642 | Francesco Colista | 2017-08-09 | 2 | -5/+47 | |
| | ||||||
* | main/libsndfile: fix for CVE-2017-12562. Fixes #7648 | Francesco Colista | 2017-08-09 | 2 | -2/+102 | |
| | ||||||
* | main/irssi: fix for CVE-2017-10965 and CVE-2017-10966. Fixes #7515 | Francesco Colista | 2017-08-09 | 2 | -4/+83 | |
| | ||||||
* | main/libmtp: security fix to 1.1.13 | Francesco Colista | 2017-08-09 | 1 | -4/+10 | |
| | | | | | | CVE-2017-9831 CVE-2017-9832 Fixes #7552 | |||||
* | main/wireshark: security fix to 2.2.8. | Francesco Colista | 2017-08-08 | 1 | -4/+8 | |
| | | | | | | | CVE-2017-11406 CVE-2017-11407 CVE-2017-11408 Fixes #7560 | |||||
* | main/spice: fix for CVE-2017-7506. Fixes #7591 | Francesco Colista | 2017-08-08 | 2 | -5/+164 | |
| | ||||||
* | main/mpg123: security upgrade to 1.25.4 (CVE-2017-9545,CVE-2017-11126) | Natanael Copa | 2017-08-07 | 1 | -4/+9 | |
| | | | | fixes #7596 | |||||
* | main/ncurses: fix for CVE-2017-10684 and CVE-2017-10685. Fixes #7565 | Francesco Colista | 2017-08-07 | 2 | -5/+215 | |
| | ||||||
* | main/bind: fix for CVE-2017-3142 and CVE-2017-3143. Fixes #7498 | Francesco Colista | 2017-08-07 | 2 | -4/+296 | |
| | ||||||
* | main/jasper: security fix CVE-2017-1000050. Fixes #7574 | Francesco Colista | 2017-08-07 | 2 | -4/+29 | |
| |