Commit Graph

11175 Commits

Author SHA1 Message Date
Michael Tremer
bb3272dad3 Start Core Update 117
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-07 16:14:36 +00:00
Michael Tremer
682a6b2dc8 unbound: Silence error when upstream name servers cannot be read
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-07 16:02:28 +01:00
Michael Tremer
a98ab1d7fd make.sh: Calculate MAKETUNING depending on available memory
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-07 15:43:14 +01:00
Michael Tremer
4f1cce84fb make.sh: Remove setting the EDITOR variable which we don't use
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-07 15:27:31 +01:00
Michael Tremer
1445a5ac43 make.sh: Add function to determine how many CPU cores the build host has
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-07 15:25:11 +01:00
Michael Tremer
7e1639a481 make.sh: Use -pipe in CFLAGS when host has >1GB of memory
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-07 15:27:00 +01:00
Michael Tremer
5190eea24f make.sh: Determine how much memory the build host has
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-07 15:25:56 +01:00
Michael Tremer
ad1204e4eb captive: One month is only 30 days instead of 210
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-06 19:07:10 +00:00
Arne Fitzenreiter
5c8acc789b core116: stop apache before extracting updated files
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-03 16:40:23 +01:00
Arne Fitzenreiter
9843bb7b5a core116: replace apache restart by stop and start
restart seems not work after replace apache...

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-03 14:28:22 +01:00
Arne Fitzenreiter
ae8e242bc1 core116: ship updated wget
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-03 14:22:19 +01:00
Arne Fitzenreiter
4f248f7a70 finish core116
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-02 22:48:58 +01:00
Arne Fitzenreiter
578171927d core116: set need_reboot flag
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-02 22:48:43 +01:00
Arne Fitzenreiter
ee328f16bf core116: ship openssh
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-02 22:46:47 +01:00
Arne Fitzenreiter
6744cd4d68 core116: fix openssl symlink
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-02 22:45:25 +01:00
Michael Tremer
770c2c5222 wget: Update file extension
Upstream does not distribute XZ compressed tarballs any more

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-02 15:38:11 +00:00
Michael Tremer
4a510319ca openssl: Update to 1.0.2m
* bn_sqrx8x_internal carry bug on x86_64 (CVE-2017-3736)
* Malformed X.509 IPAddressFamily could cause OOB read (CVE-2017-3735)

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-11-02 15:31:04 +00:00
Michael Tremer
a016c0ce6a wget: Update to 1.19.2
Fixes CVE-2017-13089

A stack-based buffer overflow when processing chunked, encoded HTTP
responses was found in wget. By tricking an unsuspecting user into
connecting to a malicious HTTP server, an attacker could exploit
this flaw to potentially execute arbitrary code.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-29 18:33:03 +00:00
Michael Tremer
7dadc13829 core116: Ship updated apache
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-28 13:36:27 +01:00
Wolfgang Apolinarski
bf24eeec20 Update to Apache 2.4.29
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-28 13:35:43 +01:00
Michael Tremer
63420a96b6 core116: Ship updated proxy.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-23 16:29:09 +01:00
Matthias Fischer
c4b12981e2 proxy.cgi: Even more cosmetics
Another clickable link for 'proxy.cgi', this time for 'Cache Manager Interface' - this one opens in a new window.

And: This time - hopefully - with correct '_blank'-attribute (deleted the backslashes) - based on current 'next'.

Plus: Deleted some "blind" tabs - found by chance.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-23 16:28:29 +01:00
Michael Tremer
b47d4bc1ea core116: Ship snort
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-23 16:26:39 +01:00
Matthias Fischer
49f7ee5d72 snort: Update to 2.9.11
For details see:

Release notes:
https://snort.org/downloads/snort/release_notes_2.9.11.txt

Changelog:
https://snort.org/downloads/snort/changelog_2.9.11.txt

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-23 16:24:46 +01:00
Michael Tremer
cd8a7fc1eb Start Core Update 116
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-23 16:24:10 +01:00
Matthias Fischer
a809d7fa68 xz: Update to 5.2.3
For details see:
https://git.tukaani.org/?p=xz.git;a=blob;f=NEWS;hb=HEAD

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-23 13:22:01 +01:00
Arne Fitzenreiter
9064ba72fe drop httpscert and merge to apache initskript
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-10-22 15:50:38 +02:00
Michael Tremer
0d6b6a219f core115: Add missing parameter to actually generate new certificates
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-21 11:20:02 +01:00
Arne Fitzenreiter
cf361ef4b5 finish core115
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-10-18 21:25:59 +02:00
Arne Fitzenreiter
fb1eb40f9b core115: add extrahd.cgi to updater
this file was missing in early core114 testbuilds so ship it again.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-10-18 21:25:45 +02:00
Arne Fitzenreiter
fcd8ab4c23 Merge branch 'master' into core115 2017-10-18 21:20:23 +02:00
Peter Müller
6c6c1e3f04 redirect to TLS WebUI if authorisation required
Do not allow credentials being submitted in plaintext to Apache.
Instead, redirect the user with a 301 to the TLS version of IPFire's
web interface.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-18 15:57:57 +01:00
Michael Tremer
348ba8e2c5 Revert "Use best XZ compression for smaller images and packages"
This reverts commit 5fd54721c2.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-18 12:35:19 +01:00
Michael Tremer
9dcfcb0039 Revert "cdrom: Use -8 as compression parameter"
This reverts commit 77ad762c43.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-18 12:35:04 +01:00
Michael Tremer
77ad762c43 cdrom: Use -8 as compression parameter
This is a better compromise on memory usage and file size

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 21:16:41 +01:00
Michael Tremer
5fd54721c2 Use best XZ compression for smaller images and packages
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 15:23:26 +01:00
Michael Tremer
c061d66fca cdrom: Change format to XZ and compress in parallel
This allows us to use all processor cores to compress
the image faster.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 14:58:52 +01:00
Michael Tremer
bc9544929c packages: Compress in parallel
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 14:58:28 +01:00
Michael Tremer
1c1babf44b captive: Fix localisations
Voucher was used instead of coupon in English, and Coupon
was used instead of Gutschein in German.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 15:11:14 +02:00
Michael Tremer
af6c5929b0 captive: Simplify coupon time selection
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 15:05:53 +02:00
Michael Tremer
f32174956e captive: Reindent code for better readability
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 12:43:42 +01:00
Michael Tremer
3a62dca68e captive: Localise GREEN/BLUE
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 12:41:17 +01:00
Michael Tremer
440cd2cbfd Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-17 12:29:22 +01:00
Michael Tremer
7207d80c4e core115: Ship logrotate
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-16 19:20:20 +01:00
Matthias Fischer
5ed7bbd52f logrotate: Update to 3.13.0
For details see:
https://github.com/logrotate/logrotate/releases

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-16 19:19:39 +01:00
Michael Tremer
b62c826fd8 PDF-API2: Add optional dependencies to read TrueType fonts
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-16 17:43:32 +01:00
Michael Tremer
e3c3625c34 Make perl-PDF-API2 part of the base system
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-16 17:31:51 +01:00
Michael Tremer
30b0e0ca1b PDF-API2: Update to 2.033
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-16 17:28:51 +01:00
Matthias Fischer
bee416e282 wpa_supplicant: Update to 2.6
For details see:
https://w1.fi/cgit/hostap/plain/wpa_supplicant/ChangeLog

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-16 17:07:18 +01:00
Michael Tremer
a10e6aaefe KRACK attack: Patch wpa_supplicant & hostapd
A vulnerability was found in how a number of implementations can be
triggered to reconfigure WPA/WPA2/RSN keys (TK, GTK, or IGTK) by
replaying a specific frame that is used to manage the keys. Such
reinstallation of the encryption key can result in two different types
of vulnerabilities: disabling replay protection and significantly
reducing the security of encryption to the point of allowing frames to
be decrypted or some parts of the keys to be determined by an attacker
depending on which cipher is used.

This fixes: CVE-2017-13077, CVE-2017-13078, CVE-2017-13079,
  CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13086,
  CVE-2017-13087, CVE-2017-13088

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-16 15:52:12 +01:00