Commit Graph

21 Commits

Author SHA1 Message Date
Michael Tremer
c0fc25861f core133: Ship updated knot package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-07 11:13:01 +01:00
Michael Tremer
e1f8f870ea core133: Ship snort configuration converter
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:42:53 +01:00
Michael Tremer
a40bcbb02c core133: Ship IPS changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:41:37 +01:00
Tim FitzGeorge
a5ba473c15 suricata: correct rule actions in IPS mode
In IPS mode rule actions need to be have the action 'drop' for the
protection to work, however this is not appropriate for all rules.
Modify the generator for oinkmaster-modify-sids.conf to leave
rules with the action 'alert' here this is appropriate.  Also add
a script to be run on update to correct existing downloaded rules.

Fixes #12086

Signed-off-by: Tim FitzGeorge <ipfr@tfitzgeorge.me.uk>
Tested-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:39:57 +01:00
Michael Tremer
9734a58faf core133: Ship IDS ruleset updater
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:34:44 +01:00
Michael Tremer
dc9ac30c8d core133: Ship updated vpnmain.cgi file and regenerate configuration
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 05:08:31 +01:00
Michael Tremer
c899be2fd0 core133: Ship updated dhcp.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 00:33:36 +01:00
Michael Tremer
0bb25a4f61 SMT: Disable when system is vulnerable to L1TF (Foreshadow)
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-04 23:55:17 +01:00
Michael Tremer
d62925de4f core133: Ship updated PAM
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-04 23:32:35 +01:00
Michael Tremer
ba329dce8f core133: Ship updated rrdtool
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-04 23:31:51 +01:00
Michael Tremer
f748c79450 core133: Ship updated ovpnmain.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-02 22:49:42 +01:00
Michael Tremer
f62f432a27 openssl: Update to 1.1.1c
Fixes CVE-2019-1543

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-29 13:51:48 +01:00
Michael Tremer
7b6d2972e3 strongswan: Update to 5.8.0
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-28 13:05:50 +01:00
Michael Tremer
992fdd3d07 core133: Ship toolchain changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-28 11:44:32 +01:00
Michael Tremer
fe9dbfa124 core133: Ship updated IPS ruleset sources
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-27 15:48:44 +01:00
Michael Tremer
f6104aa1e0 core133: Drop metadata for jansson package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-27 15:42:50 +01:00
Michael Tremer
86efc510f9 core133: Ship hyperscan
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-27 15:40:31 +01:00
Arne Fitzenreiter
8a104d7f02 core133: readd late core132 changes to core133
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-05-26 17:27:16 +02:00
Michael Tremer
8feb0db430 core133: Ship updated squid
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-24 06:39:37 +01:00
Michael Tremer
53ef2a0ffe core133: Ship updated bind
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-24 06:37:21 +01:00
Michael Tremer
79967ee9c4 Start Core Update 133
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-24 06:35:46 +01:00