Commit Graph

10290 Commits

Author SHA1 Message Date
Marcel Lorenz
feba68e4af libjpeg: update to 1.4.2
The old libjpeg is renamed to libjpeg-compat
The compat makes the old libs maintainable

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Reviewed-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-26 20:18:25 +01:00
Arne Fitzenreiter
b8987235d2 Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next 2016-09-26 18:53:49 +02:00
Arne Fitzenreiter
724c0b8e4b attr: rootfile update.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-09-26 18:51:27 +02:00
Jonatan Schlag
4141e0aad1 Update krb5 to 1.14.4
This commit updates krb5 to version 1.14.4
The patch is removed, because he is upstream since 1.12.2.
The samba version is incremented, to link samba against the new krb5
version. Otherwise samba for example is linked against
/usr/lib/libkdb5.so.7 but the current version is /usr/lib/libkdb5.so.8

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-26 14:42:08 +01:00
Michael Tremer
78c3ea61b2 openssl: Update to 1.0.2j
Missing CRL sanity check (CVE-2016-7052)
========================================

Severity: Moderate

This issue only affects OpenSSL 1.0.2i, released on 22nd September 2016.

A bug fix which included a CRL sanity check was added to OpenSSL 1.1.0
but was omitted from OpenSSL 1.0.2i. As a result any attempt to use
CRLs in OpenSSL 1.0.2i will crash with a null pointer exception.

OpenSSL 1.0.2i users should upgrade to 1.0.2j

The issue was reported to OpenSSL on 22nd September 2016 by Bruce Stephens and
Thomas Jakobi. The fix was developed by Matt Caswell of the OpenSSL development
team.

https://www.openssl.org/news/secadv/20160926.txt

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-26 14:37:20 +01:00
Arne Fitzenreiter
def1ad3e94 rootfile updates: attr, ed, gawk
Check rootfiles before commit !!!

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-09-26 13:08:02 +02:00
Arne Fitzenreiter
053c554822 Revert "tcl: update to 8.6.6"
breaks kerberos (krb5) build.

This reverts commit 282dfe0bb9.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-09-26 07:17:04 +02:00
Arne Fitzenreiter
e70d2dc27d transmission: update to 2.92
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-09-24 16:44:47 +02:00
Marcel Lorenz
1031bcee20 iproute2: update to 4.7.0
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:11:30 +01:00
Marcel Lorenz
54a59fd892 usb_modeswitch_data: update to 20160803
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:08:57 +01:00
Marcel Lorenz
96f333a627 usb_modeswitch: update to 2.4.0
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:08:56 +01:00
Marcel Lorenz
2429b9210f ipset: update to 6.29
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:07:53 +01:00
Marcel Lorenz
3fc734f0f9 libmnl: update to 1.0.
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:07:13 +01:00
Marcel Lorenz
0e7699cbb5 libnetfilter_conntrack: update to 1.0.6
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:06:53 +01:00
Marcel Lorenz
087fee9c6a attr: update to 2.4.47
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:05:38 +01:00
Marcel Lorenz
6f36046c81 expat: update to 2.2.0
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:04:42 +01:00
Marcel Lorenz
b4b56b4f5c make: update to 4.2.1
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 13:03:59 +01:00
Marcel Lorenz
cde96f746a file: update to 5.28
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:56:09 +01:00
Michael Tremer
1c7a3c56ef Revert "strongswan 5.5.0: update for rootfile"
The padlock module is only built on i586

This reverts commit 2ac05ca54c.
2016-09-24 12:55:24 +01:00
Marcel Lorenz
345f1f3c0b gettext: update to 0.19.8.1
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:47:16 +01:00
Marcel Lorenz
b48a6c971e make.sh: add autoamke to toolchain to fix coreutils build fail
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:41:42 +01:00
Marcel Lorenz
35f37bf02b pkg-config: update lfs file to build with new dejagnu
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:41:41 +01:00
Marcel Lorenz
a7054dd83c dejagnu: update to 1.6
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:41:39 +01:00
Marcel Lorenz
282dfe0bb9 tcl: update to 8.6.6
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:39:41 +01:00
Marcel Lorenz
b48c31167b flex: update to 2.6.1
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:38:47 +01:00
Marcel Lorenz
7c54847dc2 diffutils: update to 3.5
Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:37:35 +01:00
Matthias Fischer
2ac05ca54c strongswan 5.5.0: update for rootfile
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:25:46 +01:00
Dirk Wagner
702bd2cd98 asterisk addon: update to 11.23.1
Changelog: http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-11-current

Signed-off-by: Dirk Wagner <dirk.wagner@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:25:46 +01:00
Dirk Wagner
e0b76ebc55 monit addon: update to 5.19.0
See changelog https://mmonit.com/monit/changes for details.

Signed-off-by: Dirk Wagner <dirk.wagner@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:25:46 +01:00
Jonatan Schlag
4c8f144e58 Fix URL to list of public name servers in dns.cgi
We have only one english wiki, so the link to the list of public
dns servers can point directly to the right page.
(The link was also not correct).

Fixes: #11191

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-24 12:25:46 +01:00
Arne Fitzenreiter
3ce7662434 Merge remote-tracking branch 'origin/core105' into next 2016-09-23 18:49:06 +02:00
Arne Fitzenreiter
2d850c7944 core105: add openssl sse2 binaries
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-09-23 10:30:34 +02:00
Arne Fitzenreiter
e4ee7f0317 core105: fix rootfile.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-09-22 17:44:06 +02:00
Michael Tremer
8029c2a899 strongswan: Update to 5.5.0
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-22 14:47:47 +01:00
Michael Tremer
f5275b5930 Merge branch 'core105' into next 2016-09-22 12:05:13 +01:00
Michael Tremer
cd805ced09 Tag Core Update 105
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-22 12:04:18 +01:00
Michael Tremer
3bc177eec5 openssl: Update to 1.0.2i
https://www.openssl.org/news/openssl-1.0.2-notes.html

This release fixes various security flaws:

* OCSP Status Request extension unbounded memory growth (CVE-2016-6304)
* SWEET32 Mitigation (CVE-2016-2183)
* OOB write in MDC2_Update() (CVE-2016-6303)
* Malformed SHA512 ticket DoS (CVE-2016-6302)
* OOB write in BN_bn2dec() (CVE-2016-2182)
* OOB read in TS_OBJ_print_bio() (CVE-2016-2180)
* Pointer arithmetic undefined behaviour (CVE-2016-2177)
* Constant time flag not preserved in DSA signing (CVE-2016-2178)
* DTLS buffered message DoS (CVE-2016-2179)
* DTLS replay protection DoS (CVE-2016-2181)
* Certificate message OOB reads (CVE-2016-6306)

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-22 12:03:56 +01:00
Michael Tremer
8bbed7a5b6 core105: Ship security update for libgcrypt
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-22 10:30:28 +01:00
Matthias Fischer
db7ef87902 libgcrypt: Update to 1.7.3
Fixes CVE-2016-6313

For details, see:
https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html
https://bugzilla.redhat.com/show_bug.cgi?id=1366105

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-22 10:30:09 +01:00
Michael Tremer
c4a1169ed9 Start Core Update 105
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-22 10:28:36 +01:00
Jonatan Schlag
ad7e47072b Libvirt: Fix update.sh script
The virtlogd could only be restarted when the daemons run. The update.sh
script tried to restart the daemon no matter if the daemons run or not.
This behaviour produce problems.

An If statement now checks if the daemon runs or not and execute the
command that is suitable for the situation.

Fixes: #11172

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-18 12:28:49 +01:00
Jonatan Schlag
59d8f64e50 Update libvirt to 2.1
This is the update of libvirt to the latest version 2.1.
The most important change from a packager view is the new virtlogd
daemon.
This daemon handles the qemu output and wrote it to log files.

The require some changes:
- A new init script to start, stop restart the daemon called virtlogd.
The daemon is restart with SIGUSR1 (this is important because the daemon
keeps all pipelines etc. open).

This introduces a problem with the uninstall.sh install.sh script.
It is not possible to stop the daemon while virtual machines are
running, so the script update.sh execute from now not uninstall.sh and
install.sh instead it contains all steps from uninstall.sh install.sh
expect the start / stop routine for virtlogd. The daemon is just
restarted after the update, which makes sure that all changes take
effect.

- new symlinks in the uninstall.sh and install.sh script and some root
file changes because of the new virtlogd init script.
- the archive format changes from tar.gz to tar.xz

For Changelogs see:

https://libvirt.org/news-2015.html
https://libvirt.org/news.html (2017 and later:
https://libvirt.org/news-2016.html )

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-18 12:28:39 +01:00
Alexander Marx
bbe8e009b8 BUG11184: Error if DNAT address ends with 0 or 255 now disabled
When using dnat addresses, it is possible to use big subnets and host addresses like 172.16.0.0/12.
These addresses where rejected because it was recognised as network address.
The check is now removed.

Signed-off-by: Alexander Marx <alexander.marx@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-15 18:58:51 +01:00
Michael Tremer
f5ab60e9aa Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-15 11:04:11 +01:00
Michael Tremer
48b1876a48 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2016-09-14 16:41:38 +01:00
Michael Tremer
3f1b94b9fa python-ipaddress: New package
Required for the unbound DHCP leases bridge

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-14 16:41:12 +01:00
Michael Tremer
d20ef9d703 unbound+DHCP: Make sure to only remove old leases and not static hosts
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-14 16:35:41 +01:00
Michael Tremer
74a5ab67fe unbound+DHCP: Read correct DHCP domain name for lease
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-14 16:29:53 +01:00
Michael Tremer
b8dd42b9a6 unbound+DHCP: Read existing leases from unbound
This allows us to restart unbound and all DHCP leases
will be re-imported even if the unbound-dhcp-leases-bridge is
not restarted.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-14 15:54:36 +01:00
Arne Fitzenreiter
ccba93959b Merge branch 'core104' into next 2016-09-13 19:41:36 +02:00