Commit Graph

13667 Commits

Author SHA1 Message Date
Matthias Fischer
8a001e556c dhcpcd: Update to 8.0.3
https://roy.marples.name/blog/dhcpcd-8-0-3-released

"DHCP: Work with IP headers with options
script: Assert that env string are correctly terminated
script: Terminate env strings with no value
script: Don't attempt to use an invalid env string
route: Fix NULL deference error when using static routes
ARP: Respect IFF_NOARP
DHCP: Add support for ARPHRD_NONE interfaces
DHCP: Allow full DHCP support for PtP interfaces, but not by default
DragonFlyBSD: 500704 announces IPv6 address flag changes
control: sends correct buffer to listeners"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-28 08:16:53 +00:00
Matthias Fischer
2b20d0cfc6 clamav: Update to 0.101.4
For details see:
https://blog.clamav.net/2019/08/clamav-01014-security-patch-release-has.html

"An out of bounds write was possible within ClamAV's NSIS bzip2
library when attempting decompression in cases where the number
of selectors exceeded the max limit set by the library (CVE-2019-12900).
The issue has been resolved by respecting that limit.

Thanks to Martin Simmons for reporting the issue here.

The zip bomb vulnerability mitigated in 0.101.3 has been assigned
the CVE identifier CVE-2019-12625. Unfortunately, a workaround for
the zip-bomb mitigation was immediately identified. To remediate
the zip-bomb scan time issue, a scan time limit has been introduced
in 0.101.4.
This limit now resolves ClamAV's vulnerability to CVE-2019-12625."

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-28 08:16:50 +00:00
Matthias Fischer
cf2aa683a9 bind: Update to 9.11.10
For details see:
https://downloads.isc.org/isc/bind9/9.11.10/RELEASE-NOTES-bind-9.11.10.html

"Security Fixes

A race condition could trigger an assertion failure when a large
number of incoming packets were being rejected.
This flaw is disclosed in CVE-2019-6471. [GL #942]"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-28 08:16:48 +00:00
Michael Tremer
84d5f2faf9 freeradius: Add a logrotate configuration file
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-28 08:16:41 +00:00
Michael Tremer
4f66bad488 dnsdist: Increase number of open files to 64k
dnsdist might need to open large number of connections
and therefore the default limit of 1024 needs to be
raised.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-28 08:16:32 +00:00
Arne Fitzenreiter
16bd7e43c1 aarch64: rootfile updates
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-26 10:12:56 +00:00
Arne Fitzenreiter
07a67eed52 core136: touch "need reboot" flag
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 17:11:29 +02:00
Arne Fitzenreiter
51a7871a35 core136: run xt_geoip_update
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 17:10:44 +02:00
Arne Fitzenreiter
ffb5a1535e core136: restart apache2
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 17:09:03 +02:00
Arne Fitzenreiter
18ec6097c3 core136: remove old perl files
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 17:05:55 +02:00
Arne Fitzenreiter
b0a8548bda core136: ship geoip-generator
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:40:49 +02:00
Arne Fitzenreiter
5c2fd2d388 core136: ship hwdata
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:37:19 +02:00
Arne Fitzenreiter
605fbc59a4 core136: ship knot
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:35:45 +02:00
Arne Fitzenreiter
7c53ccc757 core136: ship bind
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:34:37 +02:00
Arne Fitzenreiter
e2cfdbec31 core136: ship apache2
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:33:30 +02:00
Arne Fitzenreiter
906aa4741f core136: ship dhcpcd
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:31:29 +02:00
Arne Fitzenreiter
2777bc0ac4 core136: ship patch
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:28:41 +02:00
Arne Fitzenreiter
1d3287921c core136: ship ca-certificates
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:27:29 +02:00
Arne Fitzenreiter
0c9e01e64c core136: ship gcc with go compiler
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 16:25:11 +02:00
Arne Fitzenreiter
e84664b16c core136: add perl and common modules to update
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-25 12:17:41 +02:00
Arne Fitzenreiter
9e20c024b0 xt_geoip_update: fix date and add maxmind copyright to GeoIP.dat
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-24 15:44:23 +02:00
Arne Fitzenreiter
329f4a3fe1 perl-NetAddr-IP: move to core
I had added this for spamassassin but now the geoip-converter needs it too.
It was not pushed yet so there is no need to remove it from pakfire databases.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-24 11:33:45 +02:00
Arne Fitzenreiter
392994dcfb geoip-generator: added to build legacy GeoIP.dat file
program and scripts based on debian geoip packages.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-24 11:29:01 +02:00
Arne Fitzenreiter
fd24c5dcbd Merge remote-tracking branch 'arne_f/perl-5.30' into next 2019-08-20 17:43:53 +00:00
Peter Müller
66980c9e00 hwdata: update PCI/USB databases
PCI IDs: 2019-07-25 03:15:02
USB IDs: 2019-07-27 20:34:05

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:38:48 +00:00
Matthias Fischer
4bb1d994b0 knot: Update to 2.8.3
For details see:
https://www.knot-dns.cz/2019-07-16-version-283.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:38:19 +00:00
Matthias Fischer
6817d23a01 bind: Update to 9.11.9
For details see:
https://downloads.isc.org/isc/bind9/9.11.9/RELEASE-NOTES-bind-9.11.9.html

"Security Fixes

   A race condition could trigger an assertion failure when a large
   number of incoming packets were being rejected.
   This flaw is disclosed in CVE-2019-6471. [GL #942]"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:37:26 +00:00
Matthias Fischer
e83393146f apache: Update to 2.4.41
For details see:
http://mirror.dkd.de/apache//httpd/CHANGES_2.4.41

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:36:48 +00:00
Matthias Fischer
0184e5806d dhcpcd: Update to 8.0.2
For details see:
https://roy.marples.name/

"NetBSD: Can be build without ARP support but listen to kernel DaD
ND6: Removed NA support from SMALL builds
ND6: Remove and warn about NA issues on OS's other than NetBSD and Linux
script: /tmp files are now cleaned up for systems without open_memstream(3)
configure: open_memstream(3) detected on recent glibc
DHCP: Avoid duplicate read of UDP socket when BPF is also open
IP: Avoid adding address if already exists on OS other than Linux
IP6: Avoid adding address is already exists on Solaris
route: Fixed a NULL de-reference error on statically configured routes
DHCP6: Move to REQUEST when any IA has error no-binding in RENEW/REBIND
DragonFlyBSD: Now compiles and works for
IP: Accept packets with IP header options"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:36:39 +00:00
Peter Müller
f3900bc44b Postfix: update to 3.4.6
See http://www.postfix.org/announcements/postfix-3.4.6.html
for release notes.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:36:26 +00:00
Peter Müller
6fd6ab5e6f patch: update to 2.7.6
Note: This does not fix CVE-2019-13636 and CVE-2019-13638
as fixes did not make it into upstream vanilla patch, yet.

See also: https://www.debian.org/security/2019/dsa-4489

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:36:19 +00:00
Peter Müller
8de132b53d update ca-certificates CA bundle
Update the CA certificates list to what Mozilla NSS ships currently.

The original file can be retrieved from:
https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:35:54 +00:00
Arne Fitzenreiter
70571361da core136: Ship updated firewall script
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:23:34 +00:00
Peter Müller
8ee3a13552 firewall: raise log rate limit to 10 packets per second
Previous setting was to log 10 packets per minute for each
event logging is turned on. This made debugging much harder,
as the limit was rather strict and chances of dropping a
packet without logging it were good.

This patch changes the log rate limit to 10 packets per
second per event, to avoid DoS attacks against the log file.
I plan to drop log rate limit entirely in future changes,
if a better solution for this attack vector is available.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Cc: Tim FitzGeorge <ipfr@tfitzgeorge.me.uk>
Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:22:48 +00:00
Michael Tremer
d111587cc3 gcc: Build the Go compiler
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:21:08 +00:00
Michael Tremer
c4ab9992c0 freeradius: Update rootfile
This removes all SSL modules.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-08-18 17:55:35 +01:00
Michael Tremer
f53d80f60d tshark: Fix parallel build
The variable name was incorrect and therefore a parallel
build was never attempted.

This this package already takes a lot of time to build, even
more is being saved now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-08-18 17:54:01 +01:00
Arne Fitzenreiter
2de0f49f8f dhcp.cgi: fix typo
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-18 17:59:49 +02:00
Arne Fitzenreiter
00a655fa5c rootfiles: replace x86_64 with MACHINE
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-17 16:47:34 +02:00
Arne Fitzenreiter
bdde6afa76 Unix-syslog: fix rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-17 10:51:18 +02:00
Arne Fitzenreiter
2ea3f4d95f rootfiles: perl 5.30 needs the autosplit.ix files
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-17 10:42:43 +02:00
Arne Fitzenreiter
c6277d3b10 perl: remove unused patches
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 21:33:52 +02:00
Arne Fitzenreiter
b1752aa86a perl: fix installation at toolchain build
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 21:32:56 +02:00
Arne Fitzenreiter
294aa0097b perl: changes on make.sh
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 13:00:47 +02:00
Arne Fitzenreiter
8f520a2d1d rootfile update and bump of all addons with perl modules
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 12:59:46 +02:00
Arne Fitzenreiter
0eff753d71 rootfile update for all common perl modules.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 12:50:19 +02:00
Arne Fitzenreiter
7d95d6feeb spamassassin: update to 3.4.2
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 12:48:25 +02:00
Arne Fitzenreiter
cdf45e41df gnump3d: update for new perl path
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 12:47:05 +02:00
Arne Fitzenreiter
9720a361d5 mpfire: update to new perl path
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 12:45:14 +02:00
Arne Fitzenreiter
2fa5a87dc0 MIME-Tools: update to 5.509
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-16 12:42:01 +02:00