Andreas Rammhold
694676c127
Merge pull request #33964 from andir/batman-adv-2017.4
...
batman-adv 2017.4
2018-01-17 02:18:53 +00:00
Andreas Rammhold
4774356724
batman-adv: 2017.3 -> 2017.4
2018-01-17 02:55:13 +01:00
Andreas Rammhold
1eb62129d9
batman-adv: add missing nativeBuildInputs
2018-01-17 02:46:29 +01:00
Andreas Rammhold
d2b852fe7d
bind: 9.11.2 -> 9.11.2-P1 (fixes CVE-2017-3145, CVE-2017-3143, CVE-2017-3141 & CVE-2017-3140)
...
For more details see [1].
[1] http://ftp.isc.org/isc/bind9/9.11.2-P1/RELEASE-NOTES-bind-9.11.2-P1.html
2018-01-17 02:29:13 +01:00
Andreas Rammhold
1624e32eb0
Merge pull request #33929 from matthiasbeyer/update-toot
...
toot: 0.16.2 -> 0.17.1
2018-01-16 12:14:12 +00:00
Andreas Rammhold
761ed40c5c
miniupnpc_2: 2.0.20170509 -> 2.0.20171212
...
This potentially addresses CVE-2017-1000494.
Changes since last version bump:
2017/12/11:
Fix buffer over run in minixml.c
Fix uninitialized variable access in upnpreplyparse.c
2018-01-15 17:55:00 +01:00
Andreas Rammhold
addf1d5da3
miniupnpd: 2.0 -> 2.0.20171212 (fixes CVE-2017-1000494)
...
changelog since the last version bump:
2017/12/12:
Fix a few buffer overrun in SSDP and SOAP parsing
2017/11/02:
PCP : reset epoch after address change
2017/05/26:
merge https://github.com/miniupnp/miniupnp/tree/randomize_url branch
2017/05/24:
get SSDP packet receiving interface index and use it to check if the
packet is from a LAN
2017/03/13:
default to client address for AddPortMapping when <NewInternalClient>
is empty
pass ext_if_name to add_pinhole()
2016/12/23:
Fix UDA-1.2.10 Man header empty or invalid
2016/12/16:
Do not try to open IPv6 sockets once it is disabled
2016/12/01:
Fix "AddPinhole Twice" test
2016/11/11:
fixes build for Solaris/SunOS
2016/07/23:
fixes build error on DragonFly BSD
2018-01-15 17:51:19 +01:00
Andreas Rammhold
87947ca8de
Merge pull request #33873 from andir/transmission-dns-rebinding-rce
...
transmission: fix RCE via dns rebinding attach
2018-01-14 23:53:59 +00:00
Andreas Rammhold
50f48fce09
transmission: fix RCE via dns rebinding attach
...
For further details see [1] & [2].
[1] https://github.com/transmission/transmission/pull/468
[2] http://www.openwall.com/lists/oss-security/2018/01/12/1
2018-01-15 00:22:31 +01:00
Andreas Rammhold
890c8047ed
Merge pull request #33869 from dotlambda/spectre-meltdown-checker
...
spectre-meltdown-checker: 0.29 -> 0.31
2018-01-14 22:22:05 +00:00
Andreas Rammhold
856d9c2b49
Merge pull request #33739 from andir/spark
...
Apache Spark address CVE-2017-12612
2018-01-11 18:13:48 +00:00
Andreas Rammhold
3e2015c239
spark_22: 2.2.0 -> 2.2.1
2018-01-11 12:52:32 +01:00
Andreas Rammhold
e250ca072a
spark_16: removed ancient (insecure) version
2018-01-11 12:50:51 +01:00
Andreas Rammhold
9213d0cfa5
spark: mark versions <= 2.2.0 && <= 2.1.2 as insecure due to CVE-2017-12612
...
Details can be retrieve at [1].
[1] https://spark.apache.org/security.html
2018-01-11 12:45:03 +01:00
Andreas Rammhold
32f6c9a73d
Merge pull request #33633 from samueldr/feature/dbeaver
...
dbeaver: inits at 4.3.2
2018-01-10 19:30:38 +00:00
Andreas Rammhold
da1421ffdd
Merge pull request #33696 from andir/linux_4_14_13
...
Linux 4.14.13, 4.4.111, 4.9.76
2018-01-10 14:08:02 +00:00
Andreas Rammhold
f77a5ba72b
Merge pull request #33680 from flokli/notmuch
...
notmuch: 0.25.3 -> 0.26
2018-01-10 13:52:07 +00:00
Andreas Rammhold
74c9d1696f
linux_4_9: 4.9.75 -> 4.9.76
2018-01-10 13:50:49 +01:00
Andreas Rammhold
e94dab0ca3
linux_4_4: 4.4.110 -> 4.4.111
2018-01-10 13:50:49 +01:00
Andreas Rammhold
cf8021e73a
linux_4_14: 4.14.12 -> 4.14.13
...
In terms of spectre/meltdown this version also supports loading of amd
fam17h firmware.
2018-01-10 13:50:45 +01:00
Andreas Rammhold
3314c421ab
Merge pull request #33684 from andir/intel-ucode-20180108
...
microcodeIntel: 20171117 -> 20170108 (should fix CVE-2017-5715 (Spectre))
2018-01-10 02:39:10 +00:00
Andreas Rammhold
9b7ef9c738
microcodeIntel: 20171117 -> 20170108
2018-01-10 03:07:59 +01:00
Andreas Rammhold
613383206c
Merge pull request #33656 from veprbl/pyslurm_fix
...
pyslurm: bump to unbreak (master)
2018-01-09 17:24:23 +00:00
Andreas Rammhold
aff2de4909
Merge pull request #33613 from andir/linux_4_15_rc7
...
linux_testing: 4.15-rc4 -> 4.15-rc7
2018-01-09 07:39:39 +00:00
Andreas Rammhold
637d5dd00c
tomcat9: 9.0.0.M17 -> 9.0.2
...
also renamed from tomcatUnstable to tomcat9
2018-01-09 01:31:06 +01:00
Andreas Rammhold
3498654f27
tomcat7: 7.0.81 -> 7.0.82 (fixes CVE-2017-12617)
...
For details see [1].
[1] http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.82
2018-01-09 01:31:06 +01:00
Andreas Rammhold
d065224202
tomcat8: 8.0.46 -> 8.0.47 (fixes CVE-2017-12617)
...
For details see [1].
[1] http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.47
2018-01-09 01:31:06 +01:00
Andreas Rammhold
15590701e2
tomcat85: 8.5.20 -> 8.5.23 (fixes CVE-2017-12617)
...
For details see [1].
[1] http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.23
2018-01-09 01:31:06 +01:00
Andreas Rammhold
c864b07d09
linux_testing: 4.15-rc4 -> 4.15-rc7
2018-01-08 15:05:24 +01:00
Andreas Rammhold
6f61b775da
syncthing013: mark as insecure
2018-01-08 15:00:07 +01:00
Andreas Rammhold
52b8fb5d4e
syncthing012: mark as insecure
...
Also adds missing meta data.
2018-01-08 14:59:35 +01:00
Andreas Rammhold
6e2cb1dd8c
bluez: use dbus-python for the python bindings. dbus does not provide any
2018-01-06 19:09:19 +01:00
Andreas Rammhold
63ba455e53
bluez: 5.47 -> 5.48
2018-01-06 19:09:19 +01:00
Andreas Rammhold
e5715d92a7
linux_hardened_copperhead: 4.14.11a -> 4.14.12a
2018-01-06 18:40:35 +01:00
Andreas Rammhold
f61ad23a6a
irssi: 1.0.5 -> 1.0.6 (fixes CVE-2018-5206, CVE-2018-5205, CVE-2018-5208, CVE-2018-5207)
...
For details see [1].
[1] https://irssi.org/security/irssi_sa_2018_01.txt
2018-01-06 17:34:10 +01:00
Andreas Rammhold
969d61dd42
wireshark: en- & disable Gtk/Qt separately
...
This should also fix the wireshark-cli variant
2018-01-06 06:25:43 +01:00
Andreas Rammhold
c77e0539e0
wireshark-gtk: explicitly disable the Qt build when building Gtk
...
In a recent Cmake(?) or wireshark release the default behaviour did
change. A failing build log can be seen at hydra [1].
[1] https://hydra.nixos.org/build/67179559/nixlog/1
2018-01-06 05:46:23 +01:00
Andreas Rammhold
d99321cf68
blueman: add gobjectIntrospection as native build dependency
...
`gobjectIntrospection` provides a hook to fixup GI_TYPELIB_PATH.
Before this change all blueman tools fail to start because they are
unable to discover the Gtk3 libraries.
2018-01-05 13:59:25 +01:00
Andreas Rammhold
eac3d9ce69
gopass: 1.6.6 -> 1.6.7
2018-01-04 03:13:34 +01:00
Andreas Rammhold
cc097d752d
libtorrentRasterbar_1_0: removed since the last consumer is gone
2018-01-04 00:41:02 +01:00
Andreas Rammhold
9731756205
deluge: use libtorrentRasterbar instead of libtorrentRasterbar_1_0
2018-01-04 00:40:18 +01:00
Andreas Rammhold
5b72e1be76
libtorrentRasterbar: 1.1.5 -> 1.1.6
2018-01-04 00:35:40 +01:00
Andreas Rammhold
d4bc14898d
fonttools: 3.21.0 -> 3.21.1
2018-01-03 22:06:10 +01:00
Andreas Rammhold
63e3eae02f
linux: 4.14.8 -> 4.14.9
...
Besides fixes for the recent BPF issues there is also a patch included
that fixes booting on aarch64 (e.g. RPi3) ;-)
2017-12-26 15:24:49 +01:00
Andreas Rammhold
057d70ffec
gopass: init at 1.6.6
2017-12-21 12:20:07 +01:00
Andreas Rammhold
276683071b
xen: Added patches for XSA-248, XSA-249, XSA-250, XSA-251
2017-12-12 13:34:35 +01:00
Andreas Rammhold
834bdd25a3
xen: apply patches for XSA-246 & XSA-247 (CVE-2017-{17044,17045})
2017-12-12 13:20:03 +01:00
Andreas Rammhold
bb06c9ee5d
slack: 2.9.0 -> 3.0.0
2017-12-11 14:26:05 +01:00
Andreas Rammhold
f7b87a773e
pdns-recursor: 4.0.6 -> 4.0.8 (fixes CVE-2017-15120)
...
For more details see [1].
[1] http://www.openwall.com/lists/oss-security/2017/12/11/1
2017-12-11 13:51:59 +01:00
Andreas Rammhold
4314648fa1
graphicsmagick: 1.3.26 -> 1.3.27 (fixes CVE-2017-11102 amongst others)
...
See [1] for details.
[1] https://sourceforge.net/p/graphicsmagick/mailman/message/36152268/
2017-12-10 20:56:23 +01:00
Andreas Rammhold
92158e871e
uwsgi: do not touch unix.h anymore
2017-12-10 12:12:47 +01:00
Andreas Rammhold
1217ffea87
prayer: use correct include directory for c-client aka uwimap
2017-12-10 12:12:46 +01:00
Andreas Rammhold
939e71fa40
uwimap: Do not pollute include/ with headers
...
uwimap was shipping an `include/unix.h` file that would be falsely
detected by many applications (e.g. php and its modules). Due to that
file we got hacks like 8c125c0c74 .
This also adds some previously missing files that would normally be
installed by uwimap (linkage.c, osdep/unix/*.h, …)
2017-12-10 12:12:45 +01:00
Andreas Rammhold
7d7d3775e5
Revert "fix phpPackages memcache,memcached,xdebug"
...
This reverts commit 8c125c0c74 .
2017-12-10 12:12:43 +01:00
Andreas Rammhold
104de603cb
networkmanager: remove restart after suspend from resume
...
In commit ec9dc73 restarting NetworkManager after resume from
suspend/hibernate was introduced.
When I initially switch to NixOS I started noticing a high delay between
wakeup and re-connecting to WiFi & wired networks. The delay increased
from a few seconds (on my previous distro, same software stack) to
almost half a minute with NixOS.
I (locally) applied the change in this commit a few weeks ago and tested
since then. The notebook/mobile device experience has improved a lot.
Reconnects are as before switching to NixOS.
Issue #24401 could be related to this. Since I am not using KDE/plasma5
I can only guess…
2017-12-10 00:19:15 +01:00
Andreas Rammhold
241f3bb673
rawtherapee-git: remove -git version
...
As discussed in #32337 the `-git` version is outdated since a while and
doesn't compile with modern compilers anymore.
closes #32337
2017-12-09 22:04:33 +01:00
Andreas Rammhold
0841f14a8f
openssl_1_0_2: 1.0.2m -> 1.0.2n (CVE-2017-3737, CVE-2017-3738)
...
See [1] for more details
[1] https://www.openssl.org/news/secadv/20171207.txt
2017-12-09 13:15:00 +01:00
Andreas Rammhold
3d2df41a8f
rsync: fix CVE-2017-16548
2017-12-09 13:10:47 +01:00
Andreas Rammhold
4c6f7ee729
gnome2.vte: fix CVE-2012-2738
2017-12-09 12:25:04 +01:00
Andreas Rammhold
14f1698649
erlangR17: removed outdated & unused version
...
erlangR17 doesn't receive any upstream updates anymore and none of our
packages depend on it.
2017-12-08 15:06:01 +01:00
Andreas Rammhold
9f39d0ef68
erlang_basho_R16B02: OTP_16B02_basho8 -> OTP_16B02_basho10
...
Also renamed the file since it is no longer version 8.
2017-12-08 15:06:00 +01:00
Andreas Rammhold
8e2f11ee51
couchdb: use erlangR19 instead of erlangR17
...
erlangR17 is no longer receiving any kind of (security) patches,
switching to R19 should be fine as per the couchdb documentation [1]
[1] http://docs.couchdb.org/en/2.1.1/install/unix.html#dependencies
2017-12-08 15:06:00 +01:00
Andreas Rammhold
b8b4d7ebf2
erlang: removed R16.nix, was a leftover from #32443
2017-12-08 15:06:00 +01:00
Andreas Rammhold
2b72043079
erlangR16: removed outdated & unused version
...
erlangR16 doesn't receive any upstream updates anymore and none of our
packages depend on it.
2017-12-08 12:18:58 +01:00
Andreas Rammhold
2107291346
erlangR18: 18.3.4.4 -> 18.3.4.7 (fixes CVE-2017-1000385)
2017-12-08 10:27:17 +01:00
Andreas Rammhold
366355f7eb
erlangR19: 19.3 -> 19.3.6.4 (fixes CVE-2017-1000385)
2017-12-08 10:27:14 +01:00
Andreas Rammhold
175f2e147f
erlangR20: 20.1 -> 20.1.7 (fixes CVE-2017-1000385)
2017-12-08 10:27:09 +01:00
Andreas Rammhold
8ab4eb1b4c
mstpd: svn 61 -> 0.0.5.20171113
...
Also fetches package from it's new home on GitHub and fixes compilation
with gcc-7 (#31747 ).
2017-12-07 11:30:10 +01:00
Andreas Rammhold
d72974a207
qemu: apply patch for CVE-2017-17381
...
More details at [1].
[1] http://www.openwall.com/lists/oss-security/2017/12/05/2
2017-12-05 10:18:42 +01:00
Andreas Rammhold
a004f9f806
nginxModules.rtmp: v1.1.11 -> v1.2.1
...
adds support for gcc-7 and fixes nginx for #31747
2017-12-04 16:52:39 +01:00
Andreas Rammhold
93cf0ac315
dino: 2017-09-26 -> 2017-12-03
2017-12-03 23:53:49 +01:00
Andreas Rammhold
6809cb0b5f
polybar: 3.0.5 -> 3.1.0
2017-12-03 22:14:54 +01:00
Andreas Rammhold
959364c01d
tor: 0.3.1.8 -> 0.3.1.9 (CVE-2017-{8819,8820,8821,8822,8823})
...
More details in the release mail [1].
[1] https://lists.torproject.org/pipermail/tor-announce/2017-December/000147.html
2017-12-03 20:35:16 +01:00
Andreas Rammhold
fe1f228580
ffmpeg-full-3.4: apply patch for CVE-2017-16840
2017-11-28 18:41:53 +01:00
Andreas Rammhold
64d8cc7fc4
ffmpeg-full-3.4: apply patch for CVE-2017-16840
2017-11-28 00:24:02 +01:00
Andreas Rammhold
2492f45565
ffmpeg-3.4: apply fix CVE CVE-2017-16840
...
Details at [1].
[1] http://git.videolan.org/?p=ffmpeg.git;a=commit;h=a94cb36ab2ad99d3a1331c9f91831ef593d94f74
2017-11-28 00:14:05 +01:00
Andreas Rammhold
02a41b014a
ipv6calc: 0.99.2 -> 1.0.0 (also fixes gcc-7 compilation)
2017-11-26 01:41:30 +01:00
Andreas Rammhold
141644e752
conky: fix compilation with gcc-7
2017-11-25 15:57:40 +01:00
Andreas Rammhold
4bda3c4225
tracefilegen: 2015-11-14 -> 2017-05-13
...
Updated while resolving the build issue with gcc7 that is being tracked
in #31747 .
2017-11-25 14:07:07 +01:00
Andreas Rammhold
d96cac2e63
ipset: 6.27 -> 6.34
2017-11-23 20:30:22 +01:00
Andreas Rammhold
e0b95635b3
texstudio: 2.12.4 -> 2.12.6
...
changelog:
```
- use Breeze window theme on KDE Plasma 5 (thanks to Alexander Wilms)
- support single-finger panning gesture on most config dialog components
- support single-finger panning touch gesture on log viewer
- pdf viewer scroll tool: support single-finger panning gesture
- center width-constrained documents in the editor (optional)
- add document tab context menu entries "Close" and "Close All Other Documents"
- improved layout of config build page
- add system check for language tool
- change search defaults to case-insensitive (feature-requests#1254)
- tags for beamer
- change preview default to embedded pdf
- handle preview failures more gracefully, i.e. no warning pop-ups
- repect preview settings (panel,etc) also for hover preview
- show hover preview as tooltip in case of inline-mode
- warn if compiler commands are actually a command list
- several improvements to the latex parser
- notify that a restart is required when switching between modern and classic style
- improved LanguageTool communication: better error handling
- add reset to default button for some LT settings
- add 200ms delay before showing auto-hidden viewer toolbar to prevent flicker
- eye candy for pdf circular magnifier (adapted code from texworks)
- show pdf highlight in magnifier
- capslock does not close completer any more
- alternative approach for determine directories from complete texts
- use cache for previews
- auto open completer when starting to type in references, packages etc.
- scripting: editor.cutBuffer
- subframetitle in structure view
- enable inputMethod (e.g. ^) in completer
- change default for complete non-text chacters to off, as it tends to cause unexpected behaviour
- fix word separation with punctuation
- fix: remove incorrect warning "Unknown magic comment" for "% !TeX TS-program = "
- fix: avoid compile fail if magic comment program is spelled wrongly
- fix: duplicate lines in autogenerated cwl files
- fix multi line argument interpretation
- fix pdfviewer in enlarged mode
- fix editing of basic shortcuts
- fix number in length keyVals
- fix flickering in structure view
- fix crash with qimage cache
- fix crash when restoring centralVSplitterState (bug 2175)
- fix highlighting of current entry in structure
- fix Open Terminal not working on windows QTBUG-57687 (bug 2178)
- fix column detection for tabu/longtabu
```
2017-11-23 20:28:07 +01:00
Andreas Rammhold
1f0819a7cb
slack: 2.8.2 -> 2.9.0
2017-11-22 09:31:03 +01:00
Andreas Rammhold
d41d43d850
apt-cacher-ng: 0.9.1 -> 3.1
...
Also helps compilation using gcc7.
2017-11-22 09:21:58 +01:00
Andreas Rammhold
e7a65e5312
yara: 3.6.3 -> 3.7.0
2017-11-22 00:45:38 +01:00
Andreas Rammhold
f01acd4cd5
clamav: apply patch for CVE-2017-6420
...
Details at [1].
[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6420
2017-11-21 21:39:29 +01:00
Andreas Rammhold
40180335a9
wimlib: init at 1.12.0
2017-11-21 20:43:12 +01:00
Andreas Rammhold
111c8f1287
alsa-plugins: 1.1.4 -> 1.1.5
2017-11-21 20:23:38 +01:00
Andreas Rammhold
e1f8c72ec8
alsa-tools: 1.1.3 -> 1.1.5
2017-11-21 20:23:14 +01:00
Andreas Rammhold
9b8ebd8e14
alsa-utils: 1.1.4 -> 1.1.5
2017-11-21 20:22:54 +01:00
Andreas Rammhold
e207ac1ee3
alsa-lib: 1.1.4.1 -> 1.1.5
2017-11-21 20:22:14 +01:00
Andreas Rammhold
45f0c0b80e
samba: 4.6.8 -> 4.6.11 to address CVEs CVE-2017-14746 & CVE-2017-15275
...
More details at [1] & [2]
[1] https://www.samba.org/samba/security/CVE-2017-15275.html
[2] https://www.samba.org/samba/security/CVE-2017-14746.html
2017-11-21 18:11:28 +01:00
Andreas Rammhold
89fab17749
microcodeIntel: 20170707 -> 20171117
...
From the changelog:
```
Intel Processor Microcode Package for Linux
20171117 Release
-- New Platforms --
CFL U0 (06-9e-0a:22) 70
CFL B0 (06-9e-0b:2) 72
SKX H0 (06-55-04:b7) 2000035
GLK B0 (06-7a-01:1) 1e
APL Bx (06-5c-09:3) 2c
-- Updates --
KBL Y0 (06-8e-0a:c0) 66->70
-- Removed files --
SKX H0 (06-55-04:97) 2000022
```
2017-11-21 17:17:49 +01:00
Andreas Rammhold
1be0330c81
XMLLibXML: 2.0129 -> 2.0132 fixes failing tests & CVE-2017-10672
...
Issue is described in the cpan RT [1]. Patch was submitted via a GitHub PR
[2].
[1] https://rt.cpan.org/Public/Bug/Display.html?id=122958
[2] https://github.com/shlomif/perl-XML-LibXML/pull/8
2017-11-20 00:12:32 +01:00
Andreas Rammhold
e427e8415c
vagrant: removed custom rake gem
2017-11-17 11:43:31 +01:00
Andreas Rammhold
3f4eb16799
vagrant: 2.0.0 -> 2.0.1
...
Due to the virtualbox bump to version 5.2 vagrant was no longer able to
interface with virtualbox. Version 2.0.1 supports virtualbox 5.2.
2017-11-17 11:43:30 +01:00
Andreas Rammhold
17fae2499a
busybox: fix CVE-2017-1587{34}
2017-11-11 13:32:29 +01:00
Andreas Rammhold
73bec97674
libexif: fix CVE-2017-7544
...
Patch application simplified during rebasing.
2017-11-11 13:32:09 +01:00
Andreas Rammhold
4d4cd769f6
libextractor: 1.4 -> 1.6 (+ fixes multiple CVEs)
...
fixes CVE-2017-15266,CVE-2017-15267,CVE-2017-15600,CVE-2017-15601,CVE-2017-15602,CVE-2017-15922
2017-11-11 13:30:53 +01:00
Andreas Rammhold
5feed06535
babeld module: updated example config
...
Previosuly the example config did feature the deprecated `wired`
paramter. Wired can now be configured using the `type` parameter.
2017-11-10 11:54:21 +01:00
Andreas Rammhold
5d9073747a
babeld module: support non-boolean default arguments
...
Previosuly only boolean values would be rendered properly. All other
values would cause an error. Even the example configuration did fail.
2017-11-10 11:54:15 +01:00