Commit Graph

633 Commits

Author SHA1 Message Date
Thomas Heil 074bb2166e
Merge pull request #6126 from wigyori/for-15.05-pcre_nginx
CC: pcre: bump to 8.41 and fix CVEs
2018-05-25 13:52:53 +02:00
Thomas Heil 27133d6866 pcre: Added fix for CVE-2017-11164 by adding stack recursion limit
Signed-off-by: Thomas Heil <heil@terminal-consulting.de>
2018-05-24 01:32:52 +02:00
Thomas Heil 7ff17dd5a3 pcre: upgrade to version 8.41 - fixes security issues
Signed-off-by: Thomas Heil <heil@terminal-consulting.de>
2018-05-24 01:32:48 +02:00
Thomas Heil a83284d7bd fix CVE-2017-7186 Fix CVE-2017-7186 mentioned in https://bugs.exim.org/show_bug.cgi?id=2052
Signed-off-by: Thomas Heil <heil@terminal-consulting.de>
2018-05-24 01:32:44 +02:00
heil 5c64d6a6d3 package: pcre bump to version 8.40
Signed-off-by: heil <heil@terminal-consulting.de>
2018-05-24 01:32:40 +02:00
Sebastian Kemper bdfe75a5cd tiff: version bump to address open CVEs
- Bumps version to 4.0.9. Otherwise about two dozen packages would need
  to be backported. There were no ABI/API changes between 4.0.3 and
  4.0.9, so this is OK.
- Adds a patch from Jow that addresses a macro issue (already in
  master/lede-17.01)
- Adds patches copied from Debian for CVE-2017-18013 and CVE-2017-9935
  on top.

Signed-off-by: Sebastian Kemper <sebastian_ml@gmx.net>
2018-01-30 15:32:49 +01:00
Sebastian Kemper 7d2337a17f libxslt: revision bump to address open CVEs
- Add patches copied from Debian to address open CVEs
- Update mail address of maintainer
- Fix a typo
- Add --disable-silent-rules for verbose build output

Signed-off-by: Sebastian Kemper <sebastian_ml@gmx.net>
2018-01-30 15:28:35 +01:00
Sebastian Kemper f84cc525d6 libssh2: revision bump to fix CVE-2016-0787
- adds patch copied from Debian to address CVE
- fixes zlib detection
- changes http to https links
- updates maintainer's mail address

Signed-off-by: Sebastian Kemper <sebastian_ml@gmx.net>
2018-01-30 15:25:25 +01:00
Zoltan Herpai e6ff63036d
Merge pull request #5081 from wigyori/for-15.05-mxml3
CC: upgrade mxml, update download URL
2017-11-18 21:18:41 +01:00
Zoltan Herpai 9faf1ea30c
Merge pull request #5080 from wigyori/for-15.05
CC: update download URLs for various packages
2017-11-13 07:24:45 +01:00
Zoltan Herpai 330f86da51
Merge pull request #5078 from wigyori/for-15.05-neon
CC: upgrade libs/neon
2017-11-13 07:22:58 +01:00
Ted Hess b839a8a398 upmpdcli/libupnpp: Update to latest versions, refresh patch
upmpdcli: Version 1.1.3
libupnpp: Version 0.14

Signed-off-by: Ted Hess <thess@kitschensync.net>
2017-11-08 18:57:01 +01:00
Petko Bordjukov 93bc6b4141 libupnpp: Bump version to 0.11.0
This new version introduces improvements to the OpenHome support.

Signed-off-by: Petko Bordjukov <bordjukov@gmail.com>
2017-11-08 18:56:23 +01:00
Zoltan HERPAI 2a1eddb5ae libuv: move download URL to https
When using IPv6 and http://, the site redirects to https://nodejs.org
which doesn't have the dist sources. IPv4 does not have this problem.
Use https directly.

Signed-off-by: Zoltan HERPAI <wigyori@uid0.hu>
2017-11-08 18:02:59 +01:00
Othmar Truniger 8dad744f51 libesmtp: add ssl support, new upstream URL
Signed-off-by: Othmar Truniger <github@truniger.ch>
2017-11-08 09:11:04 +01:00
Alexander Ryzhov b26a06f139 libdnet: fix source URL
Signed-off-by: Alexander Ryzhov <openwrt@ryzhov-al.ru>
2017-11-08 01:54:15 +01:00
Zoltan HERPAI 72f1aa450c mxml: update download URL
Signed-off-by: Zoltan HERPAI <wigyori@uid0.hu>
2017-11-07 23:10:38 +01:00
ejurgensen cb070e6182 mxml: Update to version 2.10
Signed-off-by: Espen Jürgensen <espenjurgensen+openwrt@gmail.com>
2017-11-07 23:10:24 +01:00
ejurgensen 639241d79d mxml: update to 2.9
Signed-off-by: Espen Jürgensen <espenjurgensen+openwrt@gmail.com>
2017-11-07 23:10:22 +01:00
Zoltan HERPAI b9260db2fe neon: upgrade to 0.30.2
Signed-off-by: Zoltan HERPAI <wigyori@uid0.hu>
2017-11-07 20:28:33 +01:00
Felix Fietkau adf193882d neon: add missing dependency on zlib
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2017-11-07 20:27:06 +01:00
Zoltan HERPAI 861881c635 apr: fix download URL
Signed-off-by: Zoltan HERPAI <wigyori@uid0.hu>
2017-11-07 16:50:16 +01:00
Zoltan HERPAI c73482d074 postgresql: fix download URL
Signed-off-by: Zoltan HERPAI <wigyori@uid0.hu>
2017-11-07 16:49:54 +01:00
Kishan Gondaliya 356436f9bd libsodium: Fix download url
Signed-off-by: Kishan Gondaliya <kishanpgondaliya@gmail.com>
2017-10-31 13:46:19 +05:30
Marek Sedlak 271e054ef9 libbaudiofile: updated source url to gnome repos (v0.3.6)
Signed-off-by: Marek Sedlak bodka.zavinac@gmail.com
2016-11-27 13:18:07 +01:00
Stephan Conrad 44d8235d54 libsodium: apended /old to download url for 15.05 branch
Signed-off-by: Stephan Conrad <stephan@conrad.pics>
2016-11-24 13:37:08 +01:00
Robbie Cao 8edde98c91 libnfc: switch git repository to github
Signed-off-by: Robbie Cao <robbie.cao@gmail.com>
2016-11-12 02:52:22 -06:00
Luka Perkov b3139cf56c Revert "libwebsockets: sync with master version"
This reverts commit e245e2b824.

Signed-off-by: Luka Perkov <luka@openwrt.org>
2016-11-08 13:34:59 +01:00
Luka Perkov e245e2b824 libwebsockets: sync with master version
Signed-off-by: Luka Perkov <luka@openwrt.org>
2016-11-02 14:01:13 +01:00
W. Michael Petullo 25ef6b37f2 openldap: update to 2.4.44
Signed-off-by: W. Michael Petullo <mike@flyn.org>
2016-09-13 23:19:06 -04:00
Denis Osvald d8d457e52c libuv: bump version to 1.9.1
Signed-off-by: Denis Osvald <denis.osvald@sartura.hr>
2016-09-09 13:12:51 +02:00
Nikos Mavrogiannopoulos 2bdeefb514 gnutls: updated to 3.4.15
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-09-08 18:28:14 +02:00
Ted Hess c5dc486560 libvorbisidec: Use HTTPS for Tremor repo
Signed-off-by: Ted Hess <thess@kitschensync.net>
2016-09-08 08:38:01 -04:00
Konstantin Shalygin 47d41c531c ldns: Avoid perl bug for manpages.
Fix #2663

Signed-off-by: Konstantin Shalygin <k0ste@cn.ru>
[refresh patch]
Signed-off-by: Etienne CHAMPETIER <champetier.etienne@gmail.com>

(cherry picked from commit a4a9038f58)
2016-08-12 23:50:45 +02:00
Nikos Mavrogiannopoulos f9e2ef0543 gnutls: updated to 3.4.14
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-07-06 10:46:04 +02:00
heil bb1a9fb1fc pcre: bump to version 8.39
Signed-off-by: heil <heil@terminal-consulting.de>
2016-06-21 00:57:25 +02:00
Nikos Mavrogiannopoulos 087fa999f1 libtasn1: corrected library license
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-06-16 22:34:54 +02:00
champtar 73776792f7 Merge pull request #2782 from feckert/licenses-for-15.05
libtasn1: add license tag
2016-06-13 23:31:17 +02:00
Nikos Mavrogiannopoulos 3fe7b7b6e4 gnutls: updated to 3.4.13
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-06-12 15:36:43 +02:00
Florian Eckert 7e8a6ad18c libtasn1: add license tag
show the license for this package in opkg

Signed-off-by: Florian Eckert <Eckert.Florian@googlemail.com>
2016-05-31 14:49:11 +02:00
Nikos Mavrogiannopoulos f178723927 gnutls: updated to 3.4.12
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-05-22 17:49:28 +02:00
Nikos Mavrogiannopoulos 632c7899f7 gnutls: updated to 3.4.11
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-04-25 23:15:21 +02:00
Nikos Mavrogiannopoulos 869a5943c0 libtasn1: updated to version 4.8
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-04-25 23:15:21 +02:00
heil cc469ae468 pcre: Integrate pending patches for next upstream version 8.39
- Fix auto-callout
    (http://vcs.pcre.org/viewvc?view=rev&revision=1611)
 -  Fix negated POSIX class within negated overall class UCP
    (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1612 2f5784b3-3f2a-0410-8824-cb99058d5e15)
 - Fix bug for isolated \E between an item and its qualifier when auto callout is set.
    (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1613 2f5784b3-3f2a-0410-8824-cb99058d5e15)
 - Give error for regexec with pmatch=NULL and REG_STARTEND set
    (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1614 2f5784b3-3f2a-0410-8824-cb99058d5e15)
 - Fix \Q\E before qualifier bug when auto callouts are
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1616 2f5784b3-3f2a-0410-8824-cb99058d5e15)
 - Fix /x bug when pattern starts with white space and (?-x)
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1617 2f5784b3-3f2a-0410-8824-cb99058d5e15)
 - Fix copy named substring bug.
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1618 2f5784b3-3f2a-0410-8824-cb99058d5e15)
 - Fix (by hacking) another length computation issue.
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1619 2f5784b3-3f2a-0410-8824-cb99058d5e15

 - Fix get_substring_list() bug when \K is used in an assertion.
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1620 2f5784b3-3f2a-0410-8824-cb99058d5e15

 - Fix pcretest bad behaviour for callout in lookbehind.
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1625 2f5784b3-3f2a-0410-8824-cb99058d5e15

 - Fix workspace overflow for (*ACCEPT) with deeply nested
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1631 2f5784b3-3f2a-0410-8824-cb99058d5e15
   fixes CVE-2016-3191

 - Fix Yet another duplicate name bugfix by overestimating the memory needed (i.e. another hack - PCRE2 has this "properly" fixed).
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1636 2f5784b3-3f2a-0410-8824-cb99058d5e15

 - Fix pcretest loop for global matching with an ovector size
   (git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1637 2f5784b3-3f2a-0410-8824-cb99058d5e15

Signed-off-by: heil <heil@terminal-consulting.de>
2016-03-29 13:04:27 +02:00
Nikos Mavrogiannopoulos 1e0d97f0d8 gnutls: updated to 3.4.10
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-03-05 11:58:35 +01:00
Nikos Mavrogiannopoulos 9622fe984b gnutls: updated to 3.4.9
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-02-03 09:57:26 +01:00
heil b28b3ff56a unixodbc:
- corect fetch url

Signed-off-by: heil <heil@terminal-consulting.de>
2016-01-25 14:08:29 +01:00
heil 560cb220d2 pcre: upgrade to 0.8.38
fixes:
  * CVE 2015-2327 CVE 2015-2328 CVE 2015-8380 CVE 2015-8381 CVE
  * 2015-8382
  * CVE 2015-8383 CVE 2015-8384 CVE 2015-8385 CVE 2015-8386 CVE
  * 2015-8387
  * CVE 2015-8388 CVE 2015-8389 CVE 2015-8390 CVE 2015-8391 CVE
  * 2015-8392
  * CVE 2015-8393 CVE 2015-8394 CVE 2015-8395

Signed-off-by: heil <heil@terminal-consulting.de>
2016-01-25 14:08:12 +01:00
Nikos Mavrogiannopoulos 4a3331c47a gnutls: updated to 3.4.8
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-01-10 08:35:21 +01:00
Nikos Mavrogiannopoulos a712cfd4e6 gnutls: updated to 3.4.7
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2016-01-10 08:35:21 +01:00