aboutsummaryrefslogtreecommitdiffstats
path: root/main
Commit message (Collapse)AuthorAgeFilesLines
...
* main/xen: security fixes (CVE-2017-17044, CVE-2017-17045)Leonardo Arena2017-12-294-1/+369
| | | | Fixes #8220
* main/openssh: security fix (CVE-2017-15906)Leonardo Arena2017-12-292-3/+38
| | | | Fixes #8283
* main/heimdal: security fix (CVE-2017-17439)Leonardo Arena2017-12-292-2/+52
| | | | Fixes #8293
* main/rsync: security fixesLeonardo Arena2017-12-295-2/+149
| | | | | | CVE-2017-16548, CVE-2017-17433, CVE-2017-17434 Fixes #8319
* main/gd: security upgrade to 2.2.5 (CVE-2017-6362, CVE-2017-7890)Leonardo Arena2017-12-281-3/+8
| | | | Fixes #8329
* main/ruby: security upgrade to 2.4.3Jakub Jirutka2017-12-151-2/+4
| | | | See: https://www.ruby-lang.org/en/news/2017/12/14/ruby-2-4-3-released/
* main/openssl: security upgrade to 1.0.2nColin Williams2017-12-151-2/+5
| | | | | | | | | fixes #8275 CVE-2017-3737 CVE-2017-3738 (cherry picked from commit d2d350f8a099c9ed303f00888e05626662e5c7f6)
* main/bacula: fix rundirLeonardo Arena2017-12-084-5/+17
|
* main/redis: upgrade to 3.2.11Jakub Jirutka2017-12-071-2/+2
|
* main/samba: security upgrade to 4.6.11 (CVE-2017-14746,CVE-2017-15275)Natanael Copa2017-12-071-2/+2
| | | | fixes #8182
* main/tevent: upgrade to 0.9.34Natanael Copa2017-12-071-4/+2
|
* main/talloc: upgrade to 2.1.10Natanael Copa2017-12-071-2/+2
|
* main/ffmpeg: ssecurity upgrade to 3.2.9Natanael Copa2017-12-071-2/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixes #8206 3.2.9-r0: - CVE-2017-15186 3.2.8-r0: - CVE-2017-14054 - CVE-2017-14055 - CVE-2017-14056 - CVE-2017-14057 - CVE-2017-14058 - CVE-2017-14059 - CVE-2017-14169 - CVE-2017-14170 - CVE-2017-14171 - CVE-2017-14222 - CVE-2017-14223 - CVE-2017-14225 - CVE-2017-14767 3.2.7-r0: - CVE-2017-11399 - CVE-2017-11665 - CVE-2017-11665 - CVE-2017-11719 3.2.6-r0: - CVE-2017-9608 - CVE-2017-9993 3.2.5-r0: - CVE-2017-9991 - CVE-2017-9992 - CVE-2017-9994 - CVE-2017-9996 3.2.4-r0: - CVE-2017-5024 - CVE-2017-5025
* main/curl: security upgrade to 7.57.0Natanael Copa2017-12-071-2/+6
| | | | | | | | CVE-2017-8816 CVE-2017-8817 CVE-2017-8818 fixes #8213
* main/pcre: add secfixes comment for CVE-2017-16231Natanael Copa2017-12-041-0/+1
| | | | | | | | We are not affected by CVE-2017-16231 due to our build with --with-match-limit-recursion=8192. We had this option since first commit, version 7.8, and were never affected. fixes #8140
* main/nginx: fix upgrade from version < 1.12.0-r1Jakub Jirutka2017-11-242-2/+29
| | | | Fixes http://bugs.alpinelinux.org/issues/8057
* main/libvorbis: fix for CVE-2017-14160Natanael Copa2017-11-232-12/+70
| | | | | | upstream issue: https://gitlab.xiph.org/xiph/vorbis/issues/2330 fixes #7938
* main/quagga: security upgrade to 1.2.2 (CVE-2017-16227)Natanael Copa2017-11-231-3/+5
| | | | fixes #8083
* main/openvpn: security upgrade to 2.4.4 (CVE-2017-12166)Natanael Copa2017-11-231-2/+2
| | | | fixes #8126
* main/busybox: secfixes for CVE-2017-15873,CVE-2017-16544Natanael Copa2017-11-233-1/+261
| | | | fixes #8188
* main/tiff: security upgrade to 4.0.9 (CVE-2017-16231,CVE-2017-16232)Natanael Copa2017-11-2319-1184/+5
| | | | fixes #8146
* main/postgresql: upgrade to 9.6.6 (security fixes)Jakub Jirutka2017-11-211-2/+5
| | | | | | | | Fixes: CVE-2017-15098, CVE-2017-15099 Release Notes: https://www.postgresql.org/about/news/1801/ PostgreSQL on Alpine has never been affected by CVE-2017-12172.
* main/varnish: security upgrade to 4.1.9 (CVE-2017-8807)Natanael Copa2017-11-213-154/+17
| | | | fixes #8165
* main/libvirt: security fix (CVE 2017-1000256). Fixes #8158Francesco Colista2017-11-212-2/+48
|
* main/openssl: security upgrade to 1.0.2mAndy Postnikov2017-11-091-2/+5
| | | | | | | | | CVE-2017-3735 CVE-2017-3736 fixes #8114 (cherry picked from commit c57b41c34309ede6b832e2edc306f6ab14a5d78c)
* main/openssl: upgrade to 1.0.2l, modernize aportTimo Teräs2017-11-091-31/+6
| | | | (cherry picked from commit da64f1dce381d98a8e06b16a19b5aea1d01170c4)
* main/lxc: add fixed patchJakub Jirutka2017-10-311-5/+5
|
* main/lxc: upgrade to 2.0.9 (bugfixes)Jakub Jirutka2017-10-313-85/+4
|
* main/apk-tools: upgrade to 2.7.4Timo Teräs2017-10-271-2/+2
|
* main/binutils: security fix (CVE-2017-9038)Leonardo Arena2017-10-252-3/+40
| | | | partially fixes #7315
* main/xen: security fixesLeonardo Arena2017-10-255-2/+383
| | | | | | (CVE-2017-14316, CVE-2017-14317, CVE-2017-14318, CVE-2017-14319) fixes #7820
* main/gdk-pixbuf: security upgrade to 2.36.7 (CVE-2017-2862)Leonardo Arena2017-10-251-3/+5
| | | | Fixes #7866
* main/newsbeuter: security fix (CVE-2017-14500)Leonardo Arena2017-10-242-3/+47
| | | | fixes #7877
* main/curl: security upgrade to 7.56.1 (CVE-2017-1000257)Natanael Copa2017-10-241-2/+4
| | | | fixes #8039
* main/samba: security upgrade to 4.6.8Leonardo Arena2017-10-242-49/+9
| | | | | | (CVE-2017-12150, CVE-2017-12151, CVE-2017-12163) fixes #7892
* main/musl: fix CVE-2017-15650Natanael Copa2017-10-232-1/+37
| | | | fixes #8031
* main/strongswan: security fix (CVE-2017-11185)Leonardo Arena2017-10-232-1/+55
| | | | fixes #7903
* main/weechat: security fix (CVE-2017-14727)Leonardo Arena2017-10-232-2/+158
| | | | fixes #7929
* main/nginx: upgrade to 1.12.2 (bug fixes)Jakub Jirutka2017-10-231-2/+2
|
* main/mutt: Upgrade to 1.8.3.Przemyslaw Pawelczyk2017-10-201-3/+3
| | | | | | | | | "Mutt 1.8.3 was released on May 30, 2017. This is a bug-fix release, fixing a memory leak, a couple IMAP issues, and a few other small issues." -- mutt.org BTW license name in APKBUILD has been fixed to be conformant to SPDX, that we agreed to use back in June 2017 on #alpine-devel.
* Revert "main/xen,community/rng-tools: remove unicode whitespace from APKBUILDs"William Pitcock2017-10-191-1/+1
| | | | This reverts commit 94eec0c787af9a21f974d849af5a50a9e4969369.
* main/xen,community/rng-tools: remove unicode whitespace from APKBUILDsAndy Chu2017-10-191-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix bugs in 2 packages by removing Unicode whitespace. I found these problems by parsing all APKBUILD scripts with my shell (http://www.oilshell.org/). The problem only occurs if 'make' fails. Here is an excerpt: $ od -c unicode-space.sh 0000000 m a k e | | 302 240 r e t u r n 0000020 1 \n 0000022 \302 \204 is a utf-8 whitespace. No shells accept this -- it's parsed as part of the 'return' word, which makes it an invalid command. $ busybox ash unicode-space.sh make: *** No targets specified and no makefile found. Stop. unicode-space.sh: line 1:  return: not found $ bash unicode-space.sh make: *** No targets specified and no makefile found. Stop. unicode-space.sh: line 1:  return: command not found $ dash unicode-space.sh make: *** No targets specified and no makefile found. Stop. unicode-space.sh: 1: unicode-space.sh:  return: not found Remove '|| return 1' from lines that contained unicode whitespace. abuild now runs with 'set -e'.
* Revert "main/gcr: update project url and modernize"William Pitcock2017-10-191-8/+22
| | | | This reverts commit 7d3171a9ade7e7eba5469d25a350a2cc270bda68.
* main/gcr: update project url and modernizeRoberto Oliveira2017-10-191-22/+8
|
* main/automake: upgrade to 1.15.1André Klitzing2017-10-191-8/+6
|
* main/awall: upgrade to 1.4.8Kaarle Ritvanen2017-10-181-2/+2
|
* main/acf-dnsmasq: upgrade to 0.7.1Ted Trask2017-10-171-5/+3
| | | | (cherry picked from commit dad897776e7acc96e0965ded745980e2e19fd120)
* main/hostapd: security fixesLeonardo Arena2017-10-178-17/+993
| | | | | | | | | | | | | | | - CVE-2017-13077 - CVE-2017-13078 - CVE-2017-13079 - CVE-2017-13080 - CVE-2017-13081 - CVE-2017-13082 - CVE-2017-13084 (not applicable) - CVE-2017-13086 - CVE-2017-13087 - CVE-2017-13088 https://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txt
* main/wpa_supplicant: security upgradeSören Tempel2017-10-169-15/+1038
| | | | | | | | | | | | | | CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 See also: https://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txt
* main/ncurses: security upgrade to 6.0_p20170930Natanael Copa2017-10-111-13/+18
| | | | | | | | | | | | | | - CVE-2017-11112 - CVE-2017-11113 - CVE-2017-13728 - CVE-2017-13729 - CVE-2017-13730 - CVE-2017-13731 - CVE-2017-13732 - CVE-2017-13733 - CVE-2017-13734 fixes #7967