Commit Graph

773 Commits

Author SHA1 Message Date
Matthias Fischer
db017b4b6e ntp 4.2.8p5: removed obsolete patch file
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 21:18:22 +00:00
Arne Fitzenreiter
2eb67894ef binutils: update to 2.24
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-07 17:41:16 +01:00
Matthias Fischer
c3b4c861f5 dnsmasq 2.75: latest patches from upstream
Same procedure as... :-)

Best to all for xmas and 2016!

Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-28 15:35:34 +01:00
Arne Fitzenreiter
aa66842358 kernel: apply arm-multi grsecurity fixes only at arm-multi build 2015-12-23 10:14:26 +01:00
Michael Tremer
6138d53bdd lua: New package
Simple scripting language. Supposed to be fast. Needed for dnsdist.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-22 22:27:39 +00:00
Michael Tremer
f295ca0cf7 kernel: Add grsecurity compile fix
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-22 13:58:46 +00:00
Michael Tremer
8675b78af9 gcc: Update to version 4.9.3
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-22 12:43:51 +00:00
Michael Tremer
9098b1e1c0 glibc: Fix headers to build with new GCC
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-22 12:40:38 +00:00
Michael Tremer
4d7f9a81ac strongswan: Update to 5.3.5
Also ships a fix for #853 upstream.

Fixes #10998

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-19 14:09:10 +00:00
Matthias Fischer
44fb4620ee grub 2.00: Bugfix for CVE-2015-8370
See: http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html

"A vulnerability in Grub2 has been found. Versions from 1.98 (December, 2009)
to 2.02 (December, 2015) are affected. The vulnerability can be exploited
under certain circumstances, allowing local attackers to bypass any kind of
authentication (plain or hashed passwords). And so, the attacker may take
control of the computer."

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-18 23:40:00 +00:00
Matthias Fischer
1e1b03d581 dnsmasq 2.75: latest upstream patches ;-)
The neverending story continues...

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-18 15:02:30 +00:00
Matthias Fischer
fbcc3cb784 dnsmasq 2.75: latest upstream patches
Since 'Makefile' was affected, I had to rewrite
'dnsmasq-Add-support-to-read-ISC-DHCP-lease-file.patch', too.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-18 15:02:26 +00:00
Michael Tremer
93d6eed9a4 ntp: Fix syncing with local clock
This is a bug that was introduced with the latest release
from upstream

Fixes #10997
Upstream: http://bugs.ntp.org/show_bug.cgi?id=2965

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-15 12:39:19 +00:00
Michael Tremer
b1372c3bef dma: Import patch for better authentication
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-10 16:35:09 +00:00
Matthias Fischer
40e1bbda54 dnsmasq 2.75: latest upstream patches
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-01 22:35:21 +00:00
Arne Fitzenreiter
c88002c48b ipset: fix build om arm.
Never hardcode KVER-ipfire in any patches because on arm there is no KVER-ipfire kernel.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-11-07 09:11:27 +01:00
Erik Kapfer
63cbd2c1df ipset: New package
Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-11-05 11:47:14 +00:00
Arne Fitzenreiter
bd64e2a02a kernel: genksyms fix empty symbol crc.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-10-27 16:57:24 +01:00
Arne Fitzenreiter
038169b894 kernel: uppdate to 3.14.55
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-10-23 11:00:03 +02:00
Arne Fitzenreiter
52daacc5c4 kernel: update to 3.14.54
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-10-21 18:48:32 +02:00
Arne Fitzenreiter
1f011c6594 backports: add Tevii S482 patch
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-10-01 11:14:58 +02:00
Arne Fitzenreiter
1f2bda9ba3 backports: enable build on x86_64.
backports 4.1.1-1 is not stable so we need to stay on the older version.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-09-27 11:27:40 +02:00
Arne Fitzenreiter
4d4f36ef55 kernel: Update pcengines apu led patch for x86_64
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-09-20 12:46:12 +02:00
Matthias Fischer
f62ac3224c dnsmasq: latest upstream patches
dnsmasq: latest upstream patches

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-09-14 23:30:32 +01:00
Michael Tremer
27957a3f2b Merge remote-tracking branch 'ms/x86_64' into next 2015-09-11 15:06:09 +01:00
Michael Tremer
257ce821ee fireinfo: Import upstream fixes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-09-09 15:32:09 +01:00
Michael Tremer
71940784ef fireinfo: Import upstream patch
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-09-01 00:12:31 +01:00
matthias.fischer@ipfire.org
f10a246946 squid 3.4.14: Import latest patch from upstream
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-31 23:26:38 +01:00
Michael Tremer
377eaee288 openssl: Fix build on x86_64
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-22 23:29:45 +02:00
Michael Tremer
612c14d58b glibc: Fix build with make version 4.0 and greater
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-22 17:22:16 +01:00
Michael Tremer
191976efbd pcre: Fix more buffer overflows
This reverts commit cec620efdf.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-21 21:29:46 +01:00
Michael Tremer
cec620efdf Revert "pcre: Fix more buffer overflows"
This reverts commit b62425e3e3.
2015-08-19 20:30:50 +01:00
Michael Tremer
b62425e3e3 pcre: Fix more buffer overflows
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-17 23:36:36 +01:00
Matthias Fischer
f831e573d4 dnsmasq: latest upstream patches
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-17 20:53:21 +01:00
Michael Tremer
9eb008dc92 glibc: Import security fixes from upstream
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-17 20:49:34 +01:00
Michael Tremer
e628f99413 Remove left-over squid patch file 2015-08-07 20:37:53 +01:00
Michael Tremer
d08045eaa6 dnsmasq: Update to 2.75
Rather severe regression in handling DNSSEC with CNAMEs.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-08-01 20:23:34 +01:00
Michael Tremer
a722eae9dd ddns: Update to version 008
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-07-16 12:02:08 +02:00
Michael Tremer
b720e70288 cups: Update to 1.7.5 and fix for CVE-2015-1158 and CVE-2015-1159
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-07-14 17:15:00 +02:00
Michael Tremer
5929298ea1 pcre: Fix CVE-2015-5073
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-07-14 17:14:13 +02:00
Arne Fitzenreiter
c9ab30c5d3 kernel: fix trim dataloss on some solid state discs
disable trim on SuperSSpeed S238
update queued trim blacklist from kernel 4.2rc1
(add Samsung SSD 8xx and some Crucial and Micron SSD)
2015-07-13 22:00:57 +02:00
Michael Tremer
8c8383e55e Remove dnsmasq patches
These are not applied any more because dnsmasq was updated
to the latest release version.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-07-09 13:10:46 +02:00
Michael Tremer
d6c40f585d squid: Apply fix for Squid Advisory SQUID-2015:2
Squid configured with cache_peer and operating on explicit proxy
traffic does not correctly handle CONNECT method peer responses.

The bug is important because it allows remote clients to bypass
security in an explicit gateway proxy.

However, the bug is exploitable only if you have configured
cache_peer to receive CONNECT requests.

  http://www.squid-cache.org/Advisories/SQUID-2015_2.txt

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-07-09 13:10:38 +02:00
Michael Tremer
15d5073d5b Merge branch 'next' 2015-07-07 10:42:56 +02:00
Michael Tremer
3a9a74d839 python: Cleanup patches
I accidentially added a wrong patch and left in a reference
to a removed one.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-06-18 21:22:51 +02:00
Michael Tremer
67bc7ab222 python: Build libffi before python and link against it
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-06-18 21:04:19 +02:00
Michael Tremer
1ae0db1a74 Python: Update to 2.7.9
This reverts commit 3d9b9dd30e.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-06-18 21:04:18 +02:00
Michael Tremer
dff6612b02 Merge remote-tracking branch 'mfischer/dnsmasq' into next
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>

Conflicts:
	lfs/dnsmasq
2015-06-18 13:12:33 +02:00
Michael Tremer
697b4f04bf dnsmasq: Import patches from upstream
These fix minor bugs and contain smaller improvements.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-06-18 12:38:38 +02:00
Matthias Fischer
348334b6eb Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into dnsmasq 2015-06-16 21:40:16 +02:00