Commit Graph

19473 Commits

Author SHA1 Message Date
Peter Müller
e955dbdca3 Core Update 171: Ship and restart OpenVPN
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:08:25 +00:00
Adolf Belka
43ee894734 openvpn: Update to version 2.5.7
- Update from version 2.5.6 to 2.5.7
- Update of rootfile not required
- Changelog
   2.5.7. This is mostly a bugfix release, but adds limited support for OpenSSL 3.0. Full
    support will arrive in OpenVPN 2.6.
      networking: use OPENVPN_ETH_ALEN instead of ETH_ALEN
      networking_iproute2: don't pass M_WARN to openvpn_execve_check()
      t_net.sh: delete dummy iface using iproute command
      auth-pam.c: add missing include limits.h
      Add insecure tls-cert-profile options
      Refactor early initialisation and uninitialisation into methods
      Allow loading of non default providers
      Add ubuntu 22.04 to Github Actions
      Add macos OpenSSL 3.0 and ASAN builds
      Add --with-openssl-engine autoconf option (auto|yes|no)
      Fix allowing/showing unsupported ciphers and digests
      Remove dependency on BF-CBC existance from test_ncp
      Add message when decoding PKCS12 file fails.
      Translate OpenSSL 3.0 digest names to OpenSSL 1.1 digest names
      Fix client-pending-auth error message to say ERROR instead of SUCCESS
      cipher-negotiation.rst missing from doc/Makefile.am
      vcpkg-ports\pkcs11-helper: shorten patch filename
      msvc: adjust build options to harden binaries
      vcpkg-ports: remove openssl port
      vcpkg: switch to manifest
      Fix M_ERRNO behavior on Windows
      vcpkg-ports/pkcs11-helper: bump to release 1.29
      tapctl: Resolve MSVC C4996 warnings

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:07:58 +00:00
Peter Müller
c49899dc54 Core Update 171: Ship sqlite
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:07:41 +00:00
Adolf Belka
94ed0a10e0 sqlite: Update to version 3390200
- Update from version 3390000 to 3390200
- Update of rootfile not required
- Changelog
	version 3.39.2 (2022-07-21):
	    Fix a performance regression in the query planner associated with rearranging
             the order of FROM clause terms in the presences of a LEFT JOIN.
	    Apply fixes for CVE-2022-35737, Chromium bugs 1343348 and 1345947, forum post
             3607259d3c, and other minor problems discovered by internal testing.
	version 3.39.1 (2022-07-13):
	    Fix an incorrect result from a query that uses a view that contains a
             compound SELECT in which only one arm contains a RIGHT JOIN and where the
             view is not the first FROM clause term of the query that contains the view.
             forum post 174afeae5734d42d.
	    Fix some harmless compiler warnings.
	    Fix a long-standing problem with ALTER TABLE RENAME that can only arise if
             the sqlite3_limit(SQLITE_LIMIT_SQL_LENGTH) is set to a very small value.
	    Fix a long-standing problem in FTS3 that can only arise when compiled with
             the SQLITE_ENABLE_FTS3_PARENTHESIS compile-time option.
	    Fix the build so that is works when the SQLITE_DEBUG and
             SQLITE_OMIT_WINDOWFUNC compile-time options are both provided at the same time.
	    Fix the initial-prefix optimization for the REGEXP extension so that it works
             correctly even if the prefix contains characters that require a 3-byte UTF8
             encoding.
	    Enhance the sqlite_stmt virtual table so that it buffers all of its output.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:07:32 +00:00
Peter Müller
4c4953a0d0 Core Update 171: Delete orphaned Bind libraries
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:07:03 +00:00
Peter Müller
ef0e70ee44 Core Update 171: Ship util-linux
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:05:42 +00:00
Adolf Belka
9f54f60bb1 util-linux: Update to version 2.38.1
- Update from version 2.38 to 2.38.1
- Update of rootfile not required
- Changelog
   util-linux 2.38.1 Release Notes
	BSD:
	   - Use byteswap.h and endian.h defined macos when present  [Warner Losh]
	column:
	   - fix buffer overflow when -l specified  [Karel Zak]
	   - fix greedy mode on -l  [Karel Zak]
	configure.ac:
	   - add lsns option  [Fabrice Fontaine]
	dmesg:
	   - fix --since and --until  [Karel Zak]
	docs:
	   - update AUTHORS file  [Karel Zak]
	fstrim:
	   - Remove all skipped entries before de-duplication  [Scott Shambarger]
	   - check for ENOSYS when using --quiet-unsupported  [Narthorn]
	hardlink:
	   - Document '-c' option in manpage  [FeRD (Frank Dana)]
	   - Fix man page docs for '-v/--verbose'  [FeRD (Frank Dana)]
	   - Move -c option in --help  [FeRD (Frank Dana)]
	   - require statfs_magic.h only when reflink support enabled  [Karel Zak]
	   - use info rather than warning message  [Karel Zak]
	irqtop:
	   - fix compiler warning [-Werror=format-truncation=]  [Karel Zak]
	   - remove unused variable  [Karel Zak]
	lib/fileutils:
	   - fix compiler warning  [Karel Zak]
	lib/logindefs:
	   - fix compiler warning [-Werror=format-truncation=]  [Karel Zak]
	lib/strutils:
	   - add ul_strchr_escaped()  [Karel Zak]
	libblkid:
	   - (bsd) fix buffer pointer use [fuzzing]  [Karel Zak]
	   - (hfs) fix label use [fuzzing]  [Karel Zak]
	   - (hfs) fix make sure buffer is large enough  [Karel Zak]
	   - (mac) make sure block size is large enough [fuzzing]  [Karel Zak]
	   - (probe) fix size and offset overflows [fuzzing]  [Karel Zak]
	   - (swap) fix magic string memcmp [fuzzing]  [Karel Zak]
	   - simplify 'leaf' detection  [Karel Zak]
	   - update documentation of BLOCK_SIZE tag  [Andrey Albershteyn]
	libfdisk:
	   - (gpt) Add UUID for Marvell Armada 3700 Boot partition  [Pali Rohár]
	   - meson.build fix typo  [Anatoly Pugachev]
	libmount:
	   - fix and improve utab update on MS_MOVE  [Karel Zak]
	   - when moving a mount point, all sub mount entries in utab should also be updated  [Franck Bui]
	libuuid:
	   - (man) uuid_copy() -- add missing parenthesis  [Andrew Price]
	   - improve cache handling  [d032747]
	logger:
	   - make sure structured data are escaped  [Karel Zak]
	loopdev:
	   - set block_size when using LOOP_CONFIGURE  [Hideki EIRAKU]
	losetup:
	   - Fix typo for the --sector-size docs  [Alberto Ruiz]
	lsblk:
	   - fix JSON output when without --bytes  [Karel Zak]
	lscpu:
	   - keep bogomips locale output locale sensitive  [Karel Zak]
	lsfd:
	   - add static modifier to nodev_table  [Masatake YAMATO]
	   - delete __unused__ attribute for an used parameter  [Masatake YAMATO]
	   - fix compiler warning [-Werror=maybe-uninitialized]  [Karel Zak]
	   - fix crash triggered by an empty filter expression  [Masatake YAMATO]
	lsirq:
	   - improve --sort IRQ  [Karel Zak]
	lslogins:
	   - fix free()  invalid pointer  [Karel Zak]
	   - improve prefixes interpretation  [Karel Zak]
	lsns:
	   - (man) add ip-netns to "SEE ALSO" section  [Masatake YAMATO]
	   - improve dependence on NS_GET_ ioctls  [Karel Zak]
	meson:
	   - fix compilation without systemd  [Rosen Penev]
	   - fix when HAVE_CLOCK_GETTIME is set  [Nicolas Caramelli]
	more:
	   - avoid infinite loop on --squeeze  [Karel Zak]
	po:
	   - merge changes  [Karel Zak]
	   - update de.po (from translationproject.org)  [Mario Blättermann]
	   - update hr.po (from translationproject.org)  [Božidar Putanec]
	   - update ja.po (from translationproject.org)  [Takeshi Hamasaki]
	   - update uk.po (from translationproject.org)  [Yuri Chornoivan]
	po-man:
	   - merge changes  [Karel Zak]
	   - update fr.po (from translationproject.org)  [Frédéric Marchal]
	   - update uk.po (from translationproject.org)  [Yuri Chornoivan]
	sfdiks:
	   - (man) fix example  [Karel Zak]
	sulogin:
	   - fix includes  [Karel Zak]
	switch_root:
	   - (man) fix return code description  [Karel Zak]
	taskset:
	   - fix use of  err_affinity()  [csbo98]
	tests:
	   - don't compile lsfd/mkfds helper on macos, since it's linux only  [Anatoly Pugachev]
	   - fdisk/bsd  update expected output for ppc64le  [Chris Hofstaedtler]
	   - fix misc/setarch run in a docker environment  [Anatoly Pugachev]
	   - make libmount tests more portable  [Karel Zak]
	   - report failed tests  [Karel Zak]
	unshare:
	   - Fix "you (user xxxx) don't exist" error when uid differs from primary gid  [Sol Boucher]
	uuidd:
	   - allow AF_INET in systemd service  [Karel Zak]
	   - remove also PrivateNetwork=yes from systemd service  [Karel Zak]
	zramctl:
	   - fix compiler warning [-Werror=maybe-uninitialized]  [Karel Zak]

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:04:54 +00:00
Peter Müller
a6178c7ce7 Core Update 171: Ship Bind
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:04:36 +00:00
Matthias Fischer
ceff14d956 bind: Update to 9.16.32
For details see:
https://downloads.isc.org/isc/bind9/9.16.32/doc/arm/html/notes.html#notes-for-bind-9-16-32

Excerpt from changelog:

"5934.	[func]		Improve fetches-per-zone fetch limit logging to log
			the final allowed and spilled values of the fetch
			counters before the counter object gets destroyed.
			[GL #3461]

5933.	[port]		Automatically disable RSASHA1 and NSEC3RSASHA1 in
			named on Fedorda 33, Oracle Linux 9 and RHEL9 when
			they are disabled by the security policy. [GL #3469]

5932.	[bug]		Fix rndc dumpdb -expired and always include expired
			RRsets, not just for RBTDB_VIRTUAL time window.
			[GL #3462]

5929.	[bug]		The "max-zone-ttl" option in "dnssec-policy" was
			not fully effective; it was used for timing key
			rollovers but did not actually place an upper limit
			on TTLs when loading a zone. This has been
			corrected, and the documentation has been clarified
			to indicate that the old "max-zone-ttl" zone option
			is now ignored when "dnssec-policy" is in use.
			[GL #2918]

5924.	[func]		When it's necessary to use AXFR to respond to an
			IXFR request, a message explaining the reason
			is now logged at level info. [GL #2683]

5923.	[bug]		Fix inheritance for dnssec-policy when checking for
			inline-signing. [GL #3438]

5922.	[bug]		Forwarding of UPDATE message could fail with the
			introduction of netmgr. This has been fixed. [GL #3389]"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-12 06:04:21 +00:00
Peter Müller
c5f2199d82 Core Update 171: Ship udev
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:51:42 +00:00
Adolf Belka
6a1c2abd73 udev: Update to version 3.2.11
- Update from version 3.2.6 to 3.2.11
- Update of rootfile
- Changelog
	Release 3.2.11 Latest
	    add actions workflows to check compilation on glibc and musl (devuan, alpine) by @ArsenArsen in #206
	    Add build instructions by @slicer69 in #207
	    src/libudev/conf-files.c: fix bug of using basename by @xfan1024 in #198
	    Permit eudev to work with rules which include escaped double-quotes by @slicer69 in #208
	    sync src/ata_id/ata_id.c by @bbonev in #201
	    sync src/v4l_id/v4l_id.c by @bbonev in #202
	    sync src/scsi_id/scsi_id.c by @bbonev in #203
	    sync src/mtd_probe/*.[ch] by @bbonev in #204
	    sparse: avoid clash with __bitwise and __force from 4.10 linux/types.… by @bbonev in #209
	    Silence deprecation warnings by @bbonev in #210
	    update CONTRIBUTING to reflect updated governance, clarify systemd commit hash requirements by @kaniini in #211
	    hashmap: don't initialize devt_hash_ops in the header by @kaniini in #212
	    Update to latest Devuan stable by @wwuck in #213
	    hwdb: sync with systemd/main by @bbonev in #215
	    Add getrandom(2) system call number for PowerPC by @Low-power in #216
     No changelog for versions prior to 3.2.11 found. Looks like they are in nthe systemd
      releases and not easily extracted.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:50:57 +00:00
Peter Müller
3915db3d4f Core Update 171: Ship curl
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:50:47 +00:00
Adolf Belka
a0cd3eb0f0 curl: Update to version 7.84.0
- Update from version 7.83.1 to 7.84.0
- Update of rootfile
- Changelog
	7.84.0 - June 27 2022
	 Changes:
	    curl: add --rate to set max request rate per time unit
	    curl: deprecate --random-file and --egd-file
	    curl_version_info: add CURL_VERSION_THREADSAFE
	    CURLINFO_CAPATH/CAINFO: get the default CA paths from libcurl
	    lib: make curl_global_init() threadsafe when possible
	    libssh2: add CURLOPT_SSH_HOSTKEYFUNCTION
	    opts: deprecate RANDOM_FILE and EGDSOCKET
	    socks: support unix sockets for socks proxy
	Bugfixes:
	    aws-sigv4: fix potentional NULL pointer arithmetic
	    bindlocal: don't use a random port if port number would wrap
	    c-hyper: mark status line as status for Curl_client_write()
	    ci: avoid `cmake -Hpath`
	    CI: bump FreeBSD 13.0 to 13.1
	    ci: update github actions
	    cmake: add libpsl support
	    cmake: do not add libcurl.rc to the static libcurl library
	    cmake: enable curl.rc for all Windows targets
	    cmake: fix detecting libidn2
	    cmake: support adding a suffix to the OS value
	    configure: skip libidn2 detection when winidn is used
	    configure: use the SED value to invoke sed
	    configure: warn about rustls being experimental
	    content_encoding: return error on too many compression steps
	    cookie: address secure domain overlay
	    cookie: apply limits
	    copyright.pl: parse and use .reuse/dep5 for skips
	    copyright: make repository REUSE compliant
	    curl.1: add a few see also --tls-max
	    curl.1: mention exit code zero too
	    curl: re-enable --no-remote-name
	    curl_easy_pause.3: remove explanation of progress function
	    curl_getdate.3: document that some illegal dates pass through
	    Curl_parsenetrc: don't access local pwbuf outside of scope
	    curl_url_set.3: clarify by default using known schemes only
	    CURLOPT_ALTSVC.3: document the file format
	    CURLOPT_FILETIME.3: fix the protocols this works with
	    CURLOPT_HTTPHEADER.3: improve comment in example
	    CURLOPT_NETRC.3: document the .netrc file format
	    CURLOPT_PORT.3: We discourage using this option
	    CURLOPT_RANGE.3: remove ranged upload advice
	    digest: added detection of more syntax error in server headers
	    digest: tolerate missing "realm"
	    digest: unquote realm and nonce before processing
	    DISABLED: disable 1021 for hyper again
	    docs/cmdline-opts: add copyright and license identifier to each file
	    docs/CONTRIBUTE.md: document the 'needs-votes' concept
	    docs: clarify data replacement policy for MIME API
	    doh: remove UNITTEST macro definition
	    examples/crawler.c: use the curl license
	    examples: remove fopen.c and rtsp.c
	    FAQ: Clarify Windows double quote usage
	    fopen: add Curl_fopen() for better overwriting of files
	    ftp: restore protocol state after http proxy CONNECT
	    ftp: when failing to do a secure GSSAPI login, fail hard
	    GHA/hyper: enable debug in the build
	    gssapi: improve handling of errors from gss_display_status
	    gssapi: initialize gss_buffer_desc strings
	    headers api: remove EXPERIMENTAL tag
	    http2: always debug print stream id in decimal with %u
	    http2: reject overly many push-promise headers
	    http: restore header folding behavior
	    hyper: use 'alt-used'
	    krb5: return error properly on decode errors
	    lib: make more protocol specific struct fields #ifdefed
	    libcurl-security.3: add "Secrets in memory"
	    libcurl-security.3: document CRLF header injection
	    libssh: skip the fake-close when libssh does the right thing
	    links: update dead links to the curl-wiki
	    log2changes: do not indent empty lines [ci skip]
	    macos9: remove partial support
	    Makefile.am: fix portability issues
	    Makefile.m32: delete obsolete options, improve -On [ci skip]
	    Makefile.m32: delete two obsolete OpenSSL options [ci skip]
	    Makefile.m32: stop forcing XP target with ipv6 enabled [ci skip]
	    max-time.d: clarify max-time sets max transfer time
	    mprintf: ignore clang non-literal format string
	    netrc: check %USERPROFILE% as well on Windows
	    netrc: support quoted strings
	    ngtcp2: allow curl to send larger UDP datagrams
	    ngtcp2: correct use of ngtcp2 and nghttp3 signed integer types
	    ngtcp2: enable Linux GSO
	    ngtcp2: extend QUIC transport parameters buffer
	    ngtcp2: fix alert_read_func return value
	    ngtcp2: fix typo in preprocessor condition
	    ngtcp2: handle error from ngtcp2_conn_submit_crypto_data
	    ngtcp2: send appropriate connection close error code
	    ngtcp2: support boringssl crypto backend
	    ngtcp2: use helper funcs to simplify TLS handshake integration
	    ntlm: provide a fixed fake host name
	    projects: fix third-party SSL library build paths for Visual Studio
	    quic: add Curl_quic_idle
	    quiche: support ca-fallback
	    rand: stop detecting /dev/urandom in cross-builds
	    remote-name.d: mention --output-dir
	    runtests.pl: add the --repeat parameter to the --help output
	    runtests: fix skipping tests not done event-based
	    runtests: skip starting the ssh server if user name is lacking
	    scripts/copyright.pl: fix the exclusion to not ignore man pages
	    sectransp: check for a function defined when __BLOCKS__ is undefined
	    select: return error from "lethal" poll/select errors
	    server/sws: support spaces in the HTTP request path
	    speed-limit/time.d: mention these affect transfers in either direction
	    strcase: some optimisations
	    test 2081: add a valid reply for the second request
	    test 675: add missing CR so the test passes when run through Privoxy
	    test414: add the '--resolve' keyword
	    test681: verify --no-remote-name
	    tests 266, 116 and 1540: add a small write delay
	    tests/data/test1501: kill ftp server after slow LIST response
	    tests/getpart: fix getpartattr to work with "data" and "data2"
	    tests/server/sws.c: change the HTTP writedelay unit to milliseconds
	    test{440,441,493,977}: add "HTTP proxy" keywords
	    tool_getparam: fix --parallel-max maximum value constraint
	    tool_operate: make sure --fail-with-body works with --retry
	    transfer: fix potential NULL pointer dereference
	    transfer: maintain --path-as-is after redirects
	    transfer: upload performance; avoid tiny send
	    url: free old conn better on reuse
	    url: remove redundant #ifdefs in allocate_conn()
	    url: URL encode the path when extracted, if spaces were set
	    urlapi: make curl_url_set(url, CURLUPART_URL, NULL, 0) clear all parts
	    urlapi: support CURLU_URLENCODE for curl_url_get()
	    urldata: reduce size of a few struct fields
	    urldata: remove three unused booleans from struct UserDefined
	    urldata: store tcp_keepidle and tcp_keepintvl as ints
	    version: allow stricmp() for sorting the feature list
	    vtls: make curl_global_sslset thread-safe
	    wolfssh.h: removed
	    wolfssl: correct the failf() message when a handle can't be made
	    wolfSSL: explicitly use compatibility layer
	    x509asn1: mark msnprintf return as unchecked

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-11 08:50:39 +00:00
Peter Müller
71ee5abefe Core Update 171: Ship urlfilter.dat
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:48:31 +00:00
Jon Murphy
3da3c1848e urlfilter.dat: change ipcop to ipfire
- Removed remnant from IPCop on URL Filter Logs Export page.

Signed-off-by: Jon Murphy <jon.murphy@ipfire.org>
Reviewed-by: Bernhard Bitsch <bbitsch@ipfire.org>
2022-09-11 08:48:00 +00:00
Peter Müller
a15a758292 {libvirt,qemu,samba}: Bump package versions for glibc changes
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:46:48 +00:00
Peter Müller
8f4b4833c9 Core Update 171: Ship glibc 2.36 changes
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:45:39 +00:00
Michael Tremer
c0637090b8 u-boot: Ignore LOAD segments with RWX permissions
This is a new check in binutils which has to be disabled for some legacy
bootloaders.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
2743dd7eba installer: Fix build against glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
cc388c104e syslinux: Fix build against glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
34097d0bd3 libvirt: Fix build against glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
9060a9c907 collected: Fix build with glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
692416302c qemu: Fix build against glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
b621245815 samba: Fix build with glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
fac5f144bb hdparm: Fix build with glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
03d57d8f1e libarchive: Fix build with glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
79c4be107d efivars: Fix build with glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
025c5d44de make.sh: Bump toolchain version
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
2a4ab94d1b glibc: Update to 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
a6098f80c2 binutils: Update to 2.39
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
7eda830bfd gcc: Fix build against glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Michael Tremer
11bea269b0 sysvinit: Fix build against glibc 2.36
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:36:17 +00:00
Peter Müller
608b536e78 Core Update 171: Ship kbd
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:35:48 +00:00
Peter Müller
5e39d521a8 kbd: Update to 2.5.1
Changes since 2.2.0 can be obtained from https://github.com/legionus/kbd/releases.

See also: #12857

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:35:18 +00:00
Peter Müller
ddbc886c4c Core Update 171: Ship and restart Squid
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:34:40 +00:00
Matthias Fischer
9ae861b273 squid: Update to 5.7
For details see:
http://www.squid-cache.org/Versions/v5/changesets/SQUID_5_7.html

Excerpt from changelog:
"Changes in squid-5.7 (05 Sep 2022):

	- Regression Fix: Typo in manager ACL
	- Bug 5186: noteDestinationsEnd check failed: transportWait
	- Bug 5160: Test suite fails with -flto=auto
	- Bug 3193 pt2: NTLM decoder truncating strings
	- Bug 5133: OpenSSL 3.0 support
	- ext_session_acl: fix TDB key lookup
	- forward_max_tries: Do not count discarded connections
	- ... and many compile and debugging fixes"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:33:11 +00:00
Peter Müller
41a518ae1b Core Update 171: Ship Perl changes
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:29:52 +00:00
Peter Müller
ce455a00a6 Merge branch 'next' into temp-c171-development 2022-09-11 08:20:29 +00:00
Peter Müller
a981a365a0 Core Update 170: Ship files related to #12925
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-09-11 08:13:27 +00:00
Michael Tremer
ba4f53c565 proxy.cgi: Correctly validate domain lists
Fixes: #12925 - JVN#15411362 Inquiry on vulnerability found in IPFire
Reported-by: Noriko Totsuka <vuls@jpcert.or.jp>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:12:00 +00:00
Michael Tremer
7cb63527d9 mail.cgi: Validate email recipient
The email recipient was not correctly validated which allowed for some
stored cross-site scripting vulnerability.

Fixes: #12925 - JVN#15411362 Inquiry on vulnerability found in IPFire
Reported-by: Noriko Totsuka <vuls@jpcert.or.jp>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 08:11:56 +00:00
Michael Tremer
cc826e8628 setaliases: Use "secondary" flag instead of scope
The scope option does not seem to work at all now, which is surprising
since I tested it quite well.

The secondary flag cannot be set from userspace (aparently), but it
works, so I would prefer to go with this option for now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2022-09-11 07:40:46 +00:00
Peter Müller
763efaf672 configroot: Create "settings" and "modify" files for ipblocklist
The third version of this patch conducts the necessary changes in
configroot. Previously, they took place in ipblocklist itself, which
would have caused user settings to be overwritten, should ipblocklist be
shipped in future Core Updates.

Fixes: #12917
Cc: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Stefan Schantl <stefan.schantl@ipfire.org>
2022-09-02 06:37:56 +00:00
Adolf Belka
2fbd66d90e perl-Apache-Htpasswd: Update to perl 5.36.0
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-01 21:16:51 +00:00
Adolf Belka
41b11b1654 perl-Archive-Tar: Update to perl 5.36.0
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-01 21:16:51 +00:00
Adolf Belka
9c4ca202eb perl-Archive-Zip: Update to perl 5.36.0
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-01 21:16:51 +00:00
Adolf Belka
7d9fb46e33 perl-BerkeleyDB: Update to perl 5.36.0
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-01 21:16:51 +00:00
Adolf Belka
a56c5c1bd9 perl-CGI: Update to perl 5.36.0
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-01 21:16:51 +00:00
Adolf Belka
21d7365c92 perl-Canary-Stability: Update to perl 5.36.0
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-01 21:16:51 +00:00
Adolf Belka
c32e4c3153 perl-Compress-Zlib: Update to perl 5.36.0
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
2022-09-01 21:16:51 +00:00