Files
bpfire/config/rootfiles/common
Adolf Belka 49b8893ff5 expat: Update to version 2.6.0
- Update from version 2.5.0 to 2.6.0
- Update of rootfile
- This update fixes two CVE's. Not sure if IPFire would be vulnerable or not but safer
   to update anyway.
- Changelog
    2.6.0
        Security fixes:
	      #789 #814  CVE-2023-52425 -- Fix quadratic runtime issues with big tokens
	                   that can cause denial of service, in partial where
	                   dealing with compressed XML input.  Applications
	                   that parsed a document in one go -- a single call to
	                   functions XML_Parse or XML_ParseBuffer -- were not affected.
	                   The smaller the chunks/buffers you use for parsing
	                   previously, the bigger the problem prior to the fix.
	                   Backporters should be careful to no omit parts of
	                   pull request #789 and to include earlier pull request #771,
	                   in order to not break the fix.
	           #777  CVE-2023-52426 -- Fix billion laughs attacks for users
	                   compiling *without* XML_DTD defined (which is not common).
	                   Users with XML_DTD defined have been protected since
	                   Expat >=2.4.0 (and that was CVE-2013-0340 back then).
        Bug fixes:
	            #753  Fix parse-size-dependent "invalid token" error for
	                    external entities that start with a byte order mark
	            #780  Fix NULL pointer dereference in setContext via
	                    XML_ExternalEntityParserCreate for compilation with
	                    XML_DTD undefined
	       #812 #813  Protect against closing entities out of order
        Other changes:
	            #723  Improve support for arc4random/arc4random_buf
	       #771 #788  Improve buffer growth in XML_GetBuffer and XML_Parse
	       #761 #770  xmlwf: Support --help and --version
	       #759 #770  xmlwf: Support custom buffer size for XML_GetBuffer and read
	            #744  xmlwf: Improve language and URL clickability in help output
	            #673  examples: Add new example "element_declarations.c"
	            #764  Be stricter about macro XML_CONTEXT_BYTES at build time
	            #765  Make inclusion to expat_config.h consistent
	       #726 #727  Autotools: configure.ac: Support --disable-maintainer-mode
	    #678 #705 ..
	  #706 #733 #792  Autotools: Sync CMake templates with CMake 3.26
	            #795  Autotools: Make installation of shipped man page doc/xmlwf.1
	                    independent of docbook2man availability
	            #815  Autotools|CMake: Add missing -DXML_STATIC to pkg-config file
	                    section "Cflags.private" in order to fix compilation
	                    against static libexpat using pkg-config on Windows
	       #724 #751  Autotools|CMake: Require a C99 compiler
	                    (a de-facto requirement already since Expat 2.2.2 of 2017)
	            #793  Autotools|CMake: Fix PACKAGE_BUGREPORT variable
	       #750 #786  Autotools|CMake: Make test suite require a C++11 compiler
	            #749  CMake: Require CMake >=3.5.0
	            #672  CMake: Lowercase off_t and size_t to help a bug in Meson
	            #746  CMake: Sort xmlwf sources alphabetically
	            #785  CMake|Windows: Fix generation of DLL file version info
	            #790  CMake: Build tests/benchmark/benchmark.c as well for
	                    a build with -DEXPAT_BUILD_TESTS=ON
	       #745 #757  docs: Document the importance of isFinal + adjust tests
	                    accordingly
	            #736  docs: Improve use of "NULL" and "null"
	            #713  docs: Be specific about version of XML (XML 1.0r4)
	                    and version of C (C99); (XML 1.0r5 will need a sponsor.)
	            #762  docs: reference.html: Promote function XML_ParseBuffer more
	            #779  docs: reference.html: Add HTML anchors to XML_* macros
	            #760  docs: reference.html: Upgrade to OK.css 1.2.0
	       #763 #739  docs: Fix typos
	            #696  docs|CI: Use HTTPS URLs instead of HTTP at various places
	    #669 #670 ..
	    #692 #703 ..
	       #733 #772  Address compiler warnings
	       #798 #800  Address clang-tidy warnings
	       #775 #776  Version info bumped from 9:10:8 (libexpat*.so.1.8.10)
	                    to 10:0:9 (libexpat*.so.1.9.0); see https://verbump.de/
	                    for what these numbers do
        Infrastructure:
	       #700 #701  docs: Document security policy in file SECURITY.md
	            #766  docs: Improve parse buffer variables in-code documentation
	    #674 #738 ..
	    #740 #747 ..
	  #748 #781 #782  Refactor coverage and conformance tests
	       #714 #716  Refactor debug level variables to unsigned long
	            #671  Improve handling of empty environment variable value
	                    in function getDebugLevel (without visible user effect)
	    #755 #774 ..
	    #758 #783 ..
	       #784 #787  tests: Improve test coverage with regard to parse chunk size
	  #660 #797 #801  Fuzzing: Improve fuzzing coverage
	       #367 #799  Fuzzing|CI: Start running OSS-Fuzz fuzzing regression tests
	       #698 #721  CI: Resolve some Travis CI leftovers
	            #669  CI: Be robust towards absence of Git tags
	       #693 #694  CI: Set permissions to "contents: read" for security
	            #709  CI: Pin all GitHub Actions to specific commits for security
	            #739  CI: Reject spelling errors using codespell
	            #798  CI: Enforce clang-tidy clean code
	    #773 #808 ..
	       #809 #810  CI: Upgrade Clang from 15 to 18
	            #796  CI: Start using Clang's Control Flow Integrity sanitizer
	  #675 #720 #722  CI: Adapt to breaking changes in GitHub Actions Ubuntu images
	            #689  CI: Adapt to breaking changes in Clang/LLVM Debian packaging
	            #763  CI: Adapt to breaking changes in codespell
	            #803  CI: Adapt to breaking changes in Cppcheck

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-02-09 11:24:59 +00:00
..
2024-02-02 07:33:38 +00:00
2024-01-16 15:46:37 +00:00
2024-01-31 10:27:12 +00:00
2023-04-18 21:16:24 +00:00
2023-01-23 15:21:08 +00:00
2023-04-25 12:35:52 +00:00
2023-04-18 21:17:23 +00:00
2015-12-13 22:28:15 +00:00
2024-01-23 13:57:29 +00:00
2021-02-12 11:54:42 +00:00
2020-05-01 19:08:38 +00:00
2017-06-07 09:55:27 +01:00
2020-05-09 12:03:23 +00:00
2023-12-30 06:57:50 +00:00
2021-11-24 09:09:47 +00:00
2017-09-22 18:56:04 +01:00
2021-03-29 12:53:09 +00:00
2023-01-26 23:19:05 +00:00
2018-07-14 13:43:49 +01:00
2021-05-06 09:54:21 +00:00
2023-03-05 14:15:52 +00:00
2023-05-18 09:47:47 +00:00
2021-11-19 07:03:31 +01:00
2024-01-11 11:57:25 +00:00
2023-07-26 16:09:00 +00:00
2022-02-11 09:17:36 +00:00
2018-06-25 10:54:36 +01:00
2022-02-23 15:46:45 +00:00
2017-04-17 12:36:49 +01:00
2021-10-22 09:59:20 +00:00
2021-09-05 17:48:28 +00:00
2021-03-29 12:54:50 +00:00
2024-02-07 11:01:25 +00:00
2023-03-05 15:00:03 +00:00
2021-05-20 09:47:41 +00:00
2024-02-09 11:24:59 +00:00
2021-02-03 22:23:13 +00:00
2020-11-05 23:29:18 +00:00
2021-12-09 21:04:50 +01:00
2022-02-11 09:17:46 +00:00
2017-06-07 09:55:16 +01:00
2023-09-12 16:12:53 +00:00
2021-12-09 21:08:10 +01:00
2023-07-26 16:09:00 +00:00
2023-11-21 19:09:32 +00:00
2021-10-22 16:02:22 +00:00
2023-06-24 06:34:18 +00:00
2022-01-14 13:46:00 +00:00
2024-02-01 16:07:15 +00:00
2023-07-31 09:23:21 +00:00
2023-08-08 16:02:35 +00:00
2016-08-23 13:04:47 -04:00
2024-01-23 13:58:10 +00:00
2023-07-31 09:23:03 +00:00
2020-04-30 14:52:53 +00:00
2023-11-21 19:12:54 +00:00
2018-02-11 20:56:12 +00:00
2018-07-12 10:03:34 +01:00
2022-07-11 13:04:01 +00:00
2023-11-24 13:08:30 +00:00
2023-01-05 10:47:40 +00:00
2023-01-18 23:23:06 +00:00
2023-01-05 10:47:09 +00:00
2021-11-24 09:05:10 +00:00
2023-11-21 19:01:29 +00:00
2023-08-29 09:51:28 +00:00
2023-12-07 08:08:05 +01:00
2023-01-09 18:36:05 +00:00
2024-01-11 11:57:59 +00:00
2023-01-09 18:35:20 +00:00
2023-08-29 09:54:23 +00:00
2023-12-30 07:33:44 +00:00
2022-04-30 08:56:30 +00:00
2023-07-31 09:19:33 +00:00
2023-06-15 09:35:38 +00:00
2021-04-26 17:08:53 +00:00
2022-12-26 08:30:22 +00:00
2021-04-26 17:10:13 +00:00
2022-12-27 16:26:15 +00:00
2024-01-11 11:58:34 +00:00
2022-12-17 17:20:45 +00:00
2019-12-29 19:09:27 +00:00
2024-01-23 14:00:08 +00:00
2022-05-16 07:11:45 +00:00
2022-12-27 16:24:23 +00:00
2023-08-10 06:34:27 +00:00
2016-09-24 13:07:13 +01:00
2022-12-27 16:34:44 +00:00
2015-12-11 18:47:20 +00:00
2015-06-23 13:37:57 +02:00
2023-09-12 16:14:53 +00:00
2022-09-01 21:16:50 +00:00
2023-05-03 07:28:37 +00:00
2024-01-31 10:28:33 +00:00
2022-12-27 20:44:38 +00:00
2023-11-22 21:35:32 +00:00
2024-01-11 11:59:09 +00:00
2022-11-28 13:09:53 +01:00
2023-09-12 16:15:41 +00:00
2023-01-26 23:11:22 +00:00
2023-03-05 15:13:24 +00:00
2022-01-14 20:45:24 +00:00
2021-02-22 11:28:11 +00:00
2024-01-03 21:07:37 +00:00
2022-12-26 08:40:14 +00:00
2024-01-25 10:23:03 +00:00
2023-11-22 15:26:28 +00:00
2017-04-28 13:04:19 +01:00
2023-03-05 14:53:06 +00:00
2023-11-21 19:27:56 +00:00
2023-05-03 07:48:03 +00:00
2023-01-26 23:17:50 +00:00
2021-02-05 11:24:35 +00:00
2021-02-09 12:00:04 +00:00
2021-12-03 22:51:39 +01:00
2022-05-01 08:43:14 +00:00
2020-01-04 18:23:52 +00:00
2022-11-18 14:37:25 +00:00
2024-01-03 21:21:38 +00:00
2021-01-27 21:06:57 +00:00
2023-08-24 13:42:04 +00:00
2023-01-04 21:35:28 +00:00
2021-02-08 13:51:04 +00:00
2023-06-15 09:36:10 +00:00
2023-04-18 21:09:58 +00:00
2020-12-27 10:29:55 +00:00
2018-06-30 19:51:38 +01:00
2022-03-10 10:40:37 +00:00
2016-01-10 21:18:20 +00:00
2022-06-17 10:20:18 +00:00
2023-07-26 16:09:00 +00:00
2022-04-29 18:59:39 +00:00
2024-01-30 17:40:51 +00:00
2023-12-30 07:25:59 +00:00
2024-01-23 14:01:09 +00:00
2023-03-05 15:15:10 +00:00
2023-04-24 18:54:21 +00:00
2023-06-22 21:28:05 +00:00
2021-08-16 06:52:19 +00:00
2022-12-27 16:31:06 +00:00
2022-09-01 21:16:51 +00:00
2022-09-01 21:16:51 +00:00
2022-09-01 21:16:51 +00:00
2022-09-01 21:16:51 +00:00
2022-09-01 21:16:51 +00:00
2022-09-01 21:16:50 +00:00
2022-09-01 21:16:50 +00:00
2022-09-01 21:16:50 +00:00
2024-01-23 13:55:14 +00:00
2024-01-23 13:56:08 +00:00
2021-04-10 13:39:32 +00:00
2023-08-08 16:07:28 +00:00
2023-09-12 16:18:08 +00:00
2022-12-26 08:56:24 +00:00
2023-01-19 21:38:18 +00:00
2022-02-21 21:13:50 +00:00
2023-10-30 09:53:48 +00:00
2023-12-30 06:50:03 +00:00
2022-06-17 10:20:18 +00:00
2023-03-05 14:15:52 +00:00
2017-05-19 17:44:13 +01:00
2020-08-16 10:29:42 +00:00
2022-09-01 21:16:50 +00:00
2022-02-02 19:43:26 +00:00
2022-02-09 13:48:03 +00:00
2022-02-02 19:43:24 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:24 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:24 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:25 +00:00
2022-02-09 13:48:34 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-09 13:52:30 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:26 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:24 +00:00
2022-02-02 19:43:25 +00:00
2022-02-02 19:43:27 +00:00
2022-02-02 19:43:25 +00:00
2022-07-09 14:58:58 +00:00
2018-07-12 10:03:34 +01:00
2023-04-18 21:15:28 +00:00
2020-03-29 06:34:18 +00:00
2021-03-10 13:59:29 +00:00
2022-01-14 20:25:49 +00:00
2021-10-13 12:13:04 +00:00
2021-01-06 15:21:42 +00:00
2023-11-21 19:23:18 +00:00
2023-09-19 11:06:24 +00:00
2022-11-23 12:25:36 +00:00
2021-09-05 08:42:10 +00:00
2017-01-29 19:30:13 +00:00
2022-11-29 13:42:35 +01:00
2023-10-09 08:17:23 +00:00
2023-08-30 16:16:34 +00:00
2023-11-22 21:41:02 +00:00
2023-03-04 14:07:22 +00:00
2023-10-30 09:53:48 +00:00
2023-11-21 19:06:52 +00:00
2017-04-06 10:06:08 +01:00
2023-11-21 19:23:58 +00:00
2022-07-11 13:04:05 +00:00
2020-04-30 14:56:49 +00:00
2016-07-16 10:53:53 +01:00
2021-04-26 17:04:00 +00:00
2024-01-31 10:29:13 +00:00
2020-10-15 15:33:44 +00:00
2024-01-31 10:29:47 +00:00
2023-05-03 07:52:26 +00:00