Commit Graph

5070 Commits

Author SHA1 Message Date
Arne Fitzenreiter
854b9b994c kernel: update to 4.14.20
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-02-17 20:22:39 +01:00
Arne Fitzenreiter
4cd8fd3f6d kernel: update to 4.14.19
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-02-13 14:49:32 +01:00
Arne Fitzenreiter
e9ea5b51f0 kernel: update to 4.14.18
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-02-09 21:09:31 +01:00
Arne Fitzenreiter
7baf717a40 kernel: update to 4.14.17
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-02-08 11:06:13 +01:00
Arne Fitzenreiter
c7a00111e0 kernel: update to 4.14.16
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-02-02 07:17:10 +01:00
Arne Fitzenreiter
97e4adb8fd Merge remote-tracking branch 'origin/next' into kernel-4.14 2018-01-28 11:24:12 +01:00
Matthias Fischer
9a57c6cdd3 clamav: Update to 0.99.3
Excerpt from 'README':

"ClamAV 0.99.3 is a hotfix release to patch a set of vulnerabilities.

- fixes for the following CVE's: CVE-2017-6418, CVE-2017-6420,
  CVE-2017-12374, CVE-2017-12375, CVE-2017-12376, CVE-2017-12377,
  CVE-2017-12378, CVE-2017-12379, CVE-2017-12380.
- also included are 2 minor fixes to properly detect openssl install
  locations on FreeBSD 11, and prevent false warnings about zlib 1.2.1#
  version numbers."

For details see:
http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-27 16:26:45 +00:00
Arne Fitzenreiter
b1a70cb92d Merge remote-tracking branch 'arne_f/gcc-7-retpol' into kernel-4.14 2018-01-27 13:49:35 +01:00
Arne Fitzenreiter
2d18864ae7 gcc: fix gmp download
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-01-27 13:47:09 +01:00
Arne Fitzenreiter
9b74c2a808 kernel: update to 4.14.15 2018-01-27 10:36:01 +01:00
Arne Fitzenreiter
09cdb999da Merge remote-tracking branch 'arne_f/gcc-7-retpol' into kernel-4.14 2018-01-27 10:26:11 +01:00
Arne Fitzenreiter
7520b95a8b toolchain: update to gcc-7.3.0 and enable retpolines on x86_64 and i586
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-01-26 20:48:08 +01:00
Arne Fitzenreiter
33e3a1bd84 mdadm: fix build with gcc-7 2018-01-26 12:23:00 +01:00
Arne Fitzenreiter
38391953e0 sarg: update to 2.3.11 (needed for gcc-7) 2018-01-26 12:20:57 +01:00
Arne Fitzenreiter
61b8b66667 powertop: update to v2.9 (needed for gcc-7) 2018-01-26 12:18:36 +01:00
Arne Fitzenreiter
8a366449bb bwm-ng: update to 0.6.1-f54b3fa (needed for gcc-7) 2018-01-26 12:16:37 +01:00
Arne Fitzenreiter
bb86f0f678 diffultis: update to 3.1.6 (needed for gcc-7) 2018-01-26 12:15:30 +01:00
Arne Fitzenreiter
ef17027ee8 u-boot: link missing header for gcc-7 2018-01-26 11:00:37 +01:00
Arne Fitzenreiter
4be4555fcb vdr: disabled because it will not build with gcc-7 2018-01-26 10:58:59 +01:00
Jonatan Schlag
e7edab7e55 libvirt: update to version 4.0
This version works for me. Some others do not ..

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:12:51 +00:00
Jonatan Schlag
34297a18a4 python3-libvirt: drop this package
Since it is some work to update this package accordingly to the libvirt
version  and facing the fact that I know nobody who using this I suggest to drop this. If we
need this later we can just revert the commit.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:12:49 +00:00
Jonatan Schlag
62cddc671e qemu: update to version 2.11
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:12:47 +00:00
Jonatan Schlag
939cc0932e spice: update to version 0.14
For changelog see:
https://cgit.freedesktop.org/spice/spice/tree/NEWS

This update alos fixes: CVE-2016-9577, CVE-2016-9578, CVE-2017-7506

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:12:46 +00:00
Jonatan Schlag
3019aa9970 spice-protocol: update to version 0.12.13
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:12:44 +00:00
Jonatan Schlag
4a9e4a91f0 opus: update to version 1.2.1
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:12:42 +00:00
Jonatan Schlag
e9a7dfb1fe pyparsing: update to version 2.2.0
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:12:39 +00:00
Michael Tremer
3ed1c621cf Revert "Add Intel microcode updates from Jan 2018"
This reverts commit d404b1dba2.

Intel has pulled these microcode updates because of
random system reboots and systems becoming unstable.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:08:22 +00:00
Matthias Fischer
c5845b096d wget: Update to 1.9.4
Excerpts from changelog (Details => http://git.savannah.gnu.org/cgit/wget.git):

"Switch off compression by default

	Gzip compression has a number of bugs which need to be ironed out before we can support it
	by default. Some of these stem from a misunderstanding of the HTTP spec, but a lot of them
	are also due to many web servers not
	being compliant with RFC 7231.

	With this commit, I am marking GZip compression support as experimental
	in GNU Wget pending further investigation and the addition of tests.

	* src/http.c (gethttp): Fix bug that prevented all files from being decompressed

	* src/host.c (sufmatch): Fix to domain matching

	Replace HTTP urls with HTTPS where valid

	Avoid redirecting output to file when tcgetpgrp fails
	* src/log.c (check_redirect_output): tcgetpgrp can return -1 (ENOTTY),
	be sure to check whether a valid controlling terminal exists before
	redirecting. (Fixes: #51181)

	Fix heap overflow in HTTP protocol handling (CVE-2017-13090)

	Fix stack overflow in HTTP protocol handling (CVE-2017-13089)"

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:06:53 +00:00
Matthias Fischer
be5c29b037 nano: Update to 2.9.2
For details see:
https://www.nano-editor.org/news.php

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:06:46 +00:00
Matthias Fischer
d3ae3b9974 sed: Update to 4.4
Hi,

'sed' hasn't been updated in IPFire for a few years - I thought it could
be worthy an update:

Excerpt from 'NEWS':

"* Noteworthy changes in release 4.4 (2017-02-03) [stable]

  sed could segfault when invoked with specific combination of newlines
  in the input and regex pattern. [Bug introduced in sed-4.3]"

"Noteworthy changes" from release 4.2.2 to 4.3 can be found in 'NEWS' file, too much
to list them all...

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:06:07 +00:00
Erik Kapfer
adf3f4f4fe LZ4: New compression library.
New lossless data compression algorithm.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-23 13:20:58 +00:00
Matthias Fischer
eb03c511fd squid 3.5.27: Patch for SA 2018:2
As announced, here is the second patch for 'squid 3.5.27'.

For details about this and the previous patch (2018_1) regarding "ESI Response
processing" and "HTTP message processing", see:

http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-announce-ADVISORY-SQUID-2018-1-Denial-of-Service-issue-in-ESI-Response-processing-tp4684618.html

http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-announce-ADVISORY-SQUID-2018-2-Denial-of-Service-issue-in-HTTP-Message-processing-td4684617.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-23 13:08:19 +00:00
Matthias Fischer
101765c0fd squid 3.5.27: Patch for SA 2018:1
http://www.squid-cache.org/Versions/v3/3.5/changesets/

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-23 13:07:43 +00:00
Peter Müller
4fa3d0e88e update ca-certificates CA bundle
Update the CA certificates list to what Mozilla NSS ships currently.

The original file can be retrieved from: https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-20 15:35:25 +00:00
Matthias Fischer
1bd1f34ba4 bind: Update to 9.11.2-P1
Fixes CVE-2017-3145 (https://kb.isc.org/article/AA-01542)

For details see:
http://ftp.isc.org/isc/bind9/9.11.2-P1/RELEASE-NOTES-bind-9.11.2-P1.html

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-20 15:34:01 +00:00
Matthias Fischer
6ac7b8b2a4 unbound: Update to 1.6.8
For details see:
http://www.unbound.net/download.html

Fixes CVE-2017-15105: vulnerability in the processing of wildcard synthesized NSEC records,
=> https://unbound.net/downloads/CVE-2017-15105.txt

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-20 14:37:25 +00:00
Jonatan Schlag
2da45fe0e1 dmidecode: update to version 3.1
The removed patches are included in this version so there is no need
that we apply them.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-20 14:33:52 +00:00
Arne Fitzenreiter
2c21c4e522 Merge remote-tracking branch 'origin/next' into kernel-4.14 2018-01-15 19:08:23 +01:00
Michael Tremer
e442e02a7f glib2: Update to 2.54.3
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-14 15:44:36 +00:00
Matthias Fischer
b7a84a9402 tor: Update to 0.3.2.9
For details see:
https://gitweb.torproject.org/tor.git/plain/ReleaseNotes?id=tor-0.3.2.9

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-14 15:29:08 +00:00
Jonatan Schlag
d404b1dba2 Add Intel microcode updates from Jan 2018
Add intel microcode to the distribution and configure dracut in a way
that the microcode is loaded early in the boot process.

Fixes #11590

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Acknowledged-by: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-14 15:25:08 +00:00
Arne Fitzenreiter
5901793b61 intel-microcode: ship microcode updates (20180108)
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-01-14 11:33:13 +01:00
Arne Fitzenreiter
b715af20c9 kernel: update to 4.14.13
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-01-10 22:20:33 +01:00
Matthias Fischer
35c4e2a302 hdparm: Update to 9.53
Changes from 9.52 to 9.53:

- Read Drive Capacity fixes from Iestyn Walters.
- SET MAX ADDRESS fixes from Tom Yan <tom.ty89@gmail.com>.
- added --security-prompt-for-password to --security-help output.
- fwdownload changes from Jihoon Lee.

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-09 14:14:37 +00:00
Matthias Fischer
4d54015eb5 gzip: Update to 1.9
Excerpt from 'NEWS':

"* Noteworthy changes in release 1.9 (2018-01-07) [stable]

** Bug fixes

  gzip -d -S SUFFIX file.SUFFIX would fail for any upper-case byte in SUFFIX.
  E.g., before, this command would fail:
    $ :|gzip > kT && gzip -d -S T kT
    gzip: kT: unknown suffix -- ignored
  [bug present since the beginning]

  When decompressing data in 'pack' format, gzip no longer mishandles
  leading zeros in the end-of-block code.  [bug introduced in gzip-1.6]

  When converting from system-dependent time_t format to the 32-bit
  unsigned MTIME format used in gzip files, if a timestamp does not
  fit gzip now substitutes zero instead of the timestamp's low-order
  32 bits, as per Internet RFC 1952.  When converting from MTIME to
  time_t format, if a timestamp does not fit gzip now warns and
  substitutes the nearest in-range value instead of crashing or
  silently substituting an implementation-defined value (typically,
  the timestamp's low-order bits).  This affects timestamps before
  1970 and after 2106, and timestamps after 2038 on platforms with
  32-bit signed time_t.  [bug present since the beginning]

  Commands implemented via shell scripts are now more consistent about
  failure status.  For example, 'gunzip --help >/dev/full' now
  consistently exits with status 1 (error), instead of with status 2
  (warning) on some platforms.  [bug present since the beginning]

  Support for VMS and Amiga has been removed.  It was not working anyway,
  and it reportedly caused file name glitches on MS-Windowsish platforms."

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-09 14:14:37 +00:00
Michael Tremer
ddcd60f7dc mdns-repeater: New package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-09 14:14:37 +00:00
Matthias Fischer
74713741e6 snort: Update to 2.9.11.1
For details see:

Release notes:
https://snort.org/downloads/snort/release_notes_2.9.11.1.txt

Changelog:
https://snort.org/downloads/snort/changelog_2.9.11.1.txt

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-07 19:20:32 +00:00
Arne Fitzenreiter
6d295033e1 kernel: update to 4.14.12
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-01-05 23:31:54 +01:00
Michael Tremer
91bd66d6d1 Drop PHP
This is no longer needed and in the telephone conference
on Dec 4th, it was decided to drop it.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-05 13:37:25 +00:00
Michael Tremer
333915f5cf Drop owncloud
We are going to remove PHP and owncloud requires it

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-05 13:28:59 +00:00