aboutsummaryrefslogtreecommitdiffstats
path: root/main
Commit message (Collapse)AuthorAgeFilesLines
...
* main/perl: security upgrade to 5.24.3 (CVE-2017-12837,CVE-2017-12883)Natanael Copa2017-10-101-4/+9
| | | | fixes #7899
* main/curl: security upgrade to 7.56.0 (CVE-2017-1000254)Natanael Copa2017-10-042-40/+4
| | | | fixes #7963
* main/busybox: add secfix comment for CVE-2016-6301Natanael Copa2017-10-031-0/+4
| | | | so it gets whitelisted
* main/python3: split out wininst*.exeNatanael Copa2017-10-031-2/+9
| | | | | | | | the wininst is only needed for creating binary distribution for windows and is rarely needed. The precompiled .exe files contains statically linked version of zlib 1.2.8 which is vulnerable. Remove them from main package and save a couple of MB.
* main/sqlite: security fix for CVE-2017-10989Natanael Copa2017-10-022-1/+24
| | | | fixes #7951
* main/dnsmasq: backport patches for CVE-2017-14491..14496Jakub Jirutka2017-10-028-9/+554
|
* main/openjpeg: security upgrade to 2.2.0 and fixesFrancesco Colista2017-09-217-24/+309
| | | | | | | | | | | - CVE-2017-14040 - CVE-2017-14041 - CVE-2017-14151 - CVE-2017-14152 - CVE-2017-14164 Fixes partially #7827. Not yet fixed CVE-2017-14039 since patch is not available for 2.2.0
* main/apache2: fix CVE-2017-9798 aka OptionsbleedDaniel Isaksen2017-09-212-1/+20
|
* main/asterisk: security upgrade to 14.6.2 (CVE-2017-14099)Timo Teräs2017-09-201-2/+2
| | | | AST-2017-008 (CVE-2017-14099): RTP/RTCP information leak
* main/libgcrypt: security upgrade to 1.7.9 (CVE-2017-0378)Natanael Copa2017-09-191-4/+8
| | | | fixes #7833
* main/bluez: security fixes for CVE-2017-1000250. Fixes #7845Francesco Colista2017-09-182-4/+37
|
* main/tcpdump: upgrade to 4.9.2Andy Postnikov2017-09-151-4/+4
| | | | | Lots of security fixes http://www.tcpdump.org/tcpdump-changes.txt fixes #7840
* main/ruby: upgrade to 2.3.5 (security fixes)Jakub Jirutka2017-09-151-4/+14
|
* main/acf-lib: upgrade to 0.10.1Ted Trask2017-09-131-2/+2
| | | | (cherry picked from commit d04697c861eb21cdfe06baaee96d312586e03ee8)
* main/acf-core: upgrade to 0.21.1Ted Trask2017-09-131-2/+2
| | | | (cherry picked from commit f2933db7a757a6207ed2f57cbb0de7c1aff265db)
* main/libarchive: security fix for CVE-2017-14166. Fixes #7805Francesco Colista2017-09-112-8/+49
|
* main/oniguruma: security upgrade to 6.3.0Francesco Colista2017-09-111-4/+4
| | | | | | | | | | | fixes #7813 CVE-2017-9224 CVE-2017-9225 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 CVE-2017-9229
* main/asterisk: security upgrade to 14.6.1Timo Teräs2017-09-063-151/+357
| | | | | | | | fixes #7791 AST-2017-005: Media takeover in RTP stack AST-2017-006: Shell access command injection in app_minivm AST-2017-007: Remote Crash Vulerability in res_pjsip
* main/libraw: security fixes from debianTimo Teräs2017-09-052-7/+96
| | | | | | | fixes #7742 CVE-2017-6886 CVE-2017-6887
* main/postgresql: upgrade to 9.6.5Jakub Jirutka2017-09-051-15/+3
|
* main/libmspack: fix for CVE-2017-6419, CVE-2017-11423. Fixes #7758Francesco Colista2017-08-283-5/+117
|
* main/openjpeg: fixed patch for CVE-2017-12982Francesco Colista2017-08-232-24/+14
|
* main/openjpeg: security fix for CVE-2017-12982. Fixes #7714Francesco Colista2017-08-232-5/+36
|
* main/nss: upgrade to 3.28.4Natanael Copa2017-08-221-5/+5
| | | | fixes #7305
* main/graphite2: security upgrade to 1.3.10Natanael Copa2017-08-221-4/+4
| | | | | | | CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777, CVE-2017-7778 fixes #7428
* main/newsbeuter: security fix for CVE-2017-12904Natanael Copa2017-08-222-4/+48
| | | | fixes #7728
* main/augeas: security fix for CVE-2017-7555Natanael Copa2017-08-222-1/+168
| | | | fixes #7721
* main/mariadb: security upgrade to 10.1.26Natanael Copa2017-08-222-7/+36
| | | | | | | | | | | | | | | fixes #7706 CVE-2017-3636 CVE-2017-3641 CVE-2017-3653 CVE-2017-3308 CVE-2017-3309 CVE-2017-3453 CVE-2017-3456 CVE-2017-3464 add temp patch for libressl-2.4
* main/mercurial: security upgrade to 4.3.1Natanael Copa2017-08-191-4/+8
| | | | | | | | fixes #7693 CVE-2017-9462 CVE-2017-1000115 CVE-2017-1000116
* main/jasper: fix secfixes commentNatanael Copa2017-08-181-1/+1
|
* main/lame: fix secfixes commentNatanael Copa2017-08-181-1/+1
|
* main/supervisor: security upgrade to 3.2.4 (CVE-2017-11610). Fixes #7687Francesco Colista2017-08-171-5/+10
|
* main/c-ares: fix for CVE-2017-1000381. Fixes #7527Francesco Colista2017-08-142-5/+52
|
* main/postgresql: security upgrade to 9.6.4 ↵Natanael Copa2017-08-141-4/+8
| | | | | | (CVE-2017-7546,CVE-2017-7547,CVE-2017-7548) fixes #7662
* main/subversion: security upgrade to 1.9.7. Fixes #7669Francesco Colista2017-08-141-4/+9
|
* main/libsoup: security upgrade to 2.56.1Francesco Colista2017-08-142-4/+65
| | | | | | CVE-2017-2885 Fixes #7678
* main/curl: security upgrade to 7.55.0Natanael Copa2017-08-145-437/+45
| | | | | | | | CVE-2017-1000099 CVE-2017-1000100 CVE-2017-1000101 fixes #7655
* main/git: update to 2.11.3 (CVE-2017-1000117)Shiz2017-08-111-4/+8
|
* main/heimdal: fix for CVE-2017-11103. Fixes #7540Francesco Colista2017-08-092-4/+44
|
* main/samba: fix for CVE-2017-11103. Fixes #7534Francesco Colista2017-08-092-2/+66
|
* main/memcached: fix for CVE-2017-9951. Fixes #7642Francesco Colista2017-08-092-5/+47
|
* main/libsndfile: fix for CVE-2017-12562. Fixes #7648Francesco Colista2017-08-092-2/+102
|
* main/irssi: fix for CVE-2017-10965 and CVE-2017-10966. Fixes #7515Francesco Colista2017-08-092-4/+83
|
* main/libmtp: security fix to 1.1.13Francesco Colista2017-08-091-4/+10
| | | | | | CVE-2017-9831 CVE-2017-9832 Fixes #7552
* main/wireshark: security fix to 2.2.8.Francesco Colista2017-08-081-4/+8
| | | | | | | CVE-2017-11406 CVE-2017-11407 CVE-2017-11408 Fixes #7560
* main/spice: fix for CVE-2017-7506. Fixes #7591Francesco Colista2017-08-082-5/+164
|
* main/mpg123: security upgrade to 1.25.4 (CVE-2017-9545,CVE-2017-11126)Natanael Copa2017-08-071-4/+9
| | | | fixes #7596
* main/ncurses: fix for CVE-2017-10684 and CVE-2017-10685. Fixes #7565Francesco Colista2017-08-072-5/+215
|
* main/bind: fix for CVE-2017-3142 and CVE-2017-3143. Fixes #7498Francesco Colista2017-08-072-4/+296
|
* main/jasper: security fix CVE-2017-1000050. Fixes #7574Francesco Colista2017-08-072-4/+29
|