]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
6 years agoBump toolchain version
Michael Tremer [Mon, 12 Feb 2018 13:07:38 +0000 (13:07 +0000)] 
Bump toolchain version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoCleanup toolchain scripts
Michael Tremer [Mon, 12 Feb 2018 12:44:37 +0000 (12:44 +0000)] 
Cleanup toolchain scripts

No functional changes, just some tidy up

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoccache: Update to 3.4.1
Michael Tremer [Mon, 12 Feb 2018 12:12:08 +0000 (12:12 +0000)] 
ccache: Update to 3.4.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoPAM: Drop shipped configuration
Michael Tremer [Mon, 12 Feb 2018 12:09:22 +0000 (12:09 +0000)] 
PAM: Drop shipped configuration

This is outdated, broken and has hardcoded passwords.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop perl-DBD-mysql
Michael Tremer [Mon, 12 Feb 2018 12:07:29 +0000 (12:07 +0000)] 
Drop perl-DBD-mysql

This package is not used by anything and depends on MySQL
which has been dropped, too.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop MySQL
Michael Tremer [Mon, 12 Feb 2018 12:05:46 +0000 (12:05 +0000)] 
Drop MySQL

This is outdated and still on 5.0.x and nobody volunteered to
update this package.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoasterisk: Do not depend on MySQL any more
Michael Tremer [Mon, 12 Feb 2018 11:55:28 +0000 (11:55 +0000)] 
asterisk: Do not depend on MySQL any more

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopostfix: Don't depend on amavis
Michael Tremer [Mon, 12 Feb 2018 11:52:07 +0000 (11:52 +0000)] 
postfix: Don't depend on amavis

This can be used together but there is no need to
always install amavis when someone wants to use postfix

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopostfix: Don't depend on MySQL any more
Michael Tremer [Mon, 12 Feb 2018 11:51:46 +0000 (11:51 +0000)] 
postfix: Don't depend on MySQL any more

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopostfix: Don't ship our own configuration
Michael Tremer [Mon, 12 Feb 2018 11:50:51 +0000 (11:50 +0000)] 
postfix: Don't ship our own configuration

This is outdated and half of it is not maintained any more.

Users should configure postfix themselves based on the
default configuration.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop pammysql
Michael Tremer [Mon, 12 Feb 2018 11:44:28 +0000 (11:44 +0000)] 
Drop pammysql

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop tcpwrapper
Michael Tremer [Mon, 12 Feb 2018 11:42:47 +0000 (11:42 +0000)] 
Drop tcpwrapper

This library has been unused for quite a while

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop mISDN userspace tools
Michael Tremer [Mon, 12 Feb 2018 11:40:07 +0000 (11:40 +0000)] 
Drop mISDN userspace tools

This is unsupported for quite a while and nobody should be using this.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop capi4k-utils
Michael Tremer [Mon, 12 Feb 2018 11:33:51 +0000 (11:33 +0000)] 
Drop capi4k-utils

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore119: Remove dropped lcr package during update
Michael Tremer [Mon, 12 Feb 2018 11:31:14 +0000 (11:31 +0000)] 
core119: Remove dropped lcr package during update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore119: Import changed packages
Michael Tremer [Mon, 12 Feb 2018 11:29:53 +0000 (11:29 +0000)] 
core119: Import changed packages

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoStart Core Update 119
Michael Tremer [Mon, 12 Feb 2018 11:22:58 +0000 (11:22 +0000)] 
Start Core Update 119

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoRootfile update for bison
Michael Tremer [Mon, 12 Feb 2018 11:18:01 +0000 (11:18 +0000)] 
Rootfile update for bison

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoOpenVPN: Mark unsecure ciphers and DH-parameter as 'weak' in WUI menu
Erik Kapfer [Thu, 8 Feb 2018 08:54:58 +0000 (09:54 +0100)] 
OpenVPN: Mark unsecure ciphers and DH-parameter as 'weak' in WUI menu

64 bit block ciphers like Blowfish, TDEA and CAST5 are vulnerable to the so called 'Birthday attacks' .
    Infos for 'Sweet32' Birthday attacks can be found in here
        https://sweet32.info/ .
    An Overview of 64 bit clock ciphers can also be found in here
        http://en.citizendium.org/wiki/Block_cipher/Catalogs/Cipher_list#64-bit_blocks

1024 bit Diffie-Hellman parameter has also been marked as weak causing the 'Logjam Attack' .
   Infos for 'Logjam Attack' can be found in here
        https://weakdh.org/ .

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoindex.cgi: Properly show IPsec subnets
Michael Tremer [Sun, 11 Feb 2018 23:23:54 +0000 (23:23 +0000)] 
index.cgi: Properly show IPsec subnets

Fixes: #11604
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agomake.sh: Bump toolchain version
Michael Tremer [Sun, 11 Feb 2018 19:22:01 +0000 (19:22 +0000)] 
make.sh: Bump toolchain version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoqemu: Make it build with newer glibcs
Michael Tremer [Sun, 11 Feb 2018 19:21:20 +0000 (19:21 +0000)] 
qemu: Make it build with newer glibcs

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agonfs: Fix building with newer glibcs
Michael Tremer [Sun, 11 Feb 2018 17:12:23 +0000 (17:12 +0000)] 
nfs: Fix building with newer glibcs

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoglibc: Enable obsolete NSL
Michael Tremer [Sun, 11 Feb 2018 16:58:10 +0000 (16:58 +0000)] 
glibc: Enable obsolete NSL

This will re-activate the deprecated NIS code on which lots of
software relies on so that we can have some extra time to migrate.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoConfig: Set PREFIX either to TOOLS_DIR or /usr
Michael Tremer [Sun, 11 Feb 2018 11:35:41 +0000 (11:35 +0000)] 
Config: Set PREFIX either to TOOLS_DIR or /usr

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agomake.sh: CFLAGS: There is no evidence that supports enabling retpoline in user space...
Michael Tremer [Sun, 11 Feb 2018 11:34:47 +0000 (11:34 +0000)] 
make.sh: CFLAGS: There is no evidence that supports enabling retpoline in user space is a good idea

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agolibtirpc: Fix build against newer glibcs
Michael Tremer [Sun, 11 Feb 2018 11:34:17 +0000 (11:34 +0000)] 
libtirpc: Fix build against newer glibcs

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agobinutils: Update to 2.30
Michael Tremer [Sun, 11 Feb 2018 11:31:56 +0000 (11:31 +0000)] 
binutils: Update to 2.30

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agodma: Don't only use TLSv1
Michael Tremer [Sun, 11 Feb 2018 11:20:01 +0000 (11:20 +0000)] 
dma: Don't only use TLSv1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopostfix: Temporarily disable NIS
Michael Tremer [Sat, 10 Feb 2018 14:42:36 +0000 (14:42 +0000)] 
postfix: Temporarily disable NIS

This makes postfix FTBFS because glibc has removed their
RPC headers.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoglibc: Update to 2.27
Michael Tremer [Sat, 10 Feb 2018 14:31:21 +0000 (14:31 +0000)] 
glibc: Update to 2.27

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoflex: Patch against SEGV with newer glibc
Michael Tremer [Sat, 10 Feb 2018 13:50:53 +0000 (13:50 +0000)] 
flex: Patch against SEGV with newer glibc

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoRevert "make.sh: Add -fstack-clash-protection on platforms that support it"
Michael Tremer [Sat, 10 Feb 2018 13:30:58 +0000 (13:30 +0000)] 
Revert "make.sh: Add -fstack-clash-protection on platforms that support it"

This reverts commit 18b82970b81a5bbd31b8922440a97e43d6f01566.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agomake.sh: Enable cheap out-of-bounds checks in C++ standard library
Michael Tremer [Sat, 10 Feb 2018 13:20:14 +0000 (13:20 +0000)] 
make.sh: Enable cheap out-of-bounds checks in C++ standard library

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agomake.sh: Add -fstack-clash-protection on platforms that support it
Michael Tremer [Sat, 10 Feb 2018 13:18:42 +0000 (13:18 +0000)] 
make.sh: Add -fstack-clash-protection on platforms that support it

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agomake.sh: CFLAGS remove --param=ssp-buffer-size=4
Michael Tremer [Sat, 10 Feb 2018 13:09:00 +0000 (13:09 +0000)] 
make.sh: CFLAGS remove --param=ssp-buffer-size=4

This flag is useless with -fstack-protector-strong

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopam: Update to 1.30.0
Michael Tremer [Sat, 10 Feb 2018 12:37:46 +0000 (12:37 +0000)] 
pam: Update to 1.30.0

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agomake.sh: make requires pkg-config to run autoconf
Michael Tremer [Fri, 9 Feb 2018 17:38:08 +0000 (17:38 +0000)] 
make.sh: make requires pkg-config to run autoconf

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoiproute2: Update to 4.14.1
Michael Tremer [Fri, 9 Feb 2018 17:34:50 +0000 (17:34 +0000)] 
iproute2: Update to 4.14.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agohostname: Update to 3.20
Michael Tremer [Fri, 9 Feb 2018 17:21:59 +0000 (17:21 +0000)] 
hostname: Update to 3.20

Drops dependency to obsolete RPCSVC code in glibc.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agomake: Patch against SEGV when using globbing functions
Michael Tremer [Fri, 9 Feb 2018 17:21:12 +0000 (17:21 +0000)] 
make: Patch against SEGV when using globbing functions

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agotoolchain: Add bison
Michael Tremer [Thu, 8 Feb 2018 22:03:28 +0000 (22:03 +0000)] 
toolchain: Add bison

This is required by glibc 2.27

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agogcc: fix gmp download
Arne Fitzenreiter [Sat, 27 Jan 2018 12:47:09 +0000 (13:47 +0100)] 
gcc: fix gmp download

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 years agotoolchain: update to gcc-7.3.0 and enable retpolines on x86_64 and i586
Arne Fitzenreiter [Fri, 26 Jan 2018 19:48:08 +0000 (20:48 +0100)] 
toolchain: update to gcc-7.3.0 and enable retpolines on x86_64 and i586

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 years agomdadm: fix build with gcc-7
Arne Fitzenreiter [Fri, 26 Jan 2018 11:23:00 +0000 (12:23 +0100)] 
mdadm: fix build with gcc-7

6 years agosarg: update to 2.3.11 (needed for gcc-7)
Arne Fitzenreiter [Fri, 26 Jan 2018 11:20:57 +0000 (12:20 +0100)] 
sarg: update to 2.3.11 (needed for gcc-7)

6 years agopowertop: update to v2.9 (needed for gcc-7)
Arne Fitzenreiter [Fri, 26 Jan 2018 11:18:36 +0000 (12:18 +0100)] 
powertop: update to v2.9 (needed for gcc-7)

6 years agobwm-ng: update to 0.6.1-f54b3fa (needed for gcc-7)
Arne Fitzenreiter [Fri, 26 Jan 2018 11:16:37 +0000 (12:16 +0100)] 
bwm-ng: update to 0.6.1-f54b3fa (needed for gcc-7)

6 years agodiffultis: update to 3.1.6 (needed for gcc-7)
Arne Fitzenreiter [Fri, 26 Jan 2018 11:15:30 +0000 (12:15 +0100)] 
diffultis: update to 3.1.6 (needed for gcc-7)

6 years agou-boot: link missing header for gcc-7
Arne Fitzenreiter [Fri, 26 Jan 2018 10:00:37 +0000 (11:00 +0100)] 
u-boot: link missing header for gcc-7

6 years agovdr: disabled because it will not build with gcc-7
Arne Fitzenreiter [Fri, 26 Jan 2018 09:58:59 +0000 (10:58 +0100)] 
vdr: disabled because it will not build with gcc-7

6 years agounbound: Fix reverse lookup zones
Michael Tremer [Sun, 11 Feb 2018 17:43:43 +0000 (17:43 +0000)] 
unbound: Fix reverse lookup zones

These should be stubs and overlay the internal zones that
unbound comes with.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Fixes: #11625
6 years agoFix capitalisation of "Root Certificate"
Michael Tremer [Tue, 6 Feb 2018 15:44:57 +0000 (15:44 +0000)] 
Fix capitalisation of "Root Certificate"

Reported-by: Tom Rymes <trymes@rymes.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Fixes: #10595
6 years agoUpdate: nut to 2.7.4
Paul T. Simmons [Fri, 2 Feb 2018 21:46:49 +0000 (15:46 -0600)] 
Update: nut to 2.7.4

Signed-off-by: Paul T. Simmons <mbatranch@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agobacula: Update to 9.0.6
Michael Tremer [Fri, 2 Feb 2018 10:31:48 +0000 (10:31 +0000)] 
bacula: Update to 9.0.6

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop lcr
Michael Tremer [Thu, 11 Jan 2018 16:58:38 +0000 (16:58 +0000)] 
Drop lcr

Does not build with newer versions of Asterisk

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoasterisk: Update to 13.18.5
Michael Tremer [Thu, 11 Jan 2018 16:50:06 +0000 (16:50 +0000)] 
asterisk: Update to 13.18.5

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoAdd new package: jansson
Michael Tremer [Thu, 11 Jan 2018 12:12:38 +0000 (12:12 +0000)] 
Add new package: jansson

A JSON library required by asterisk >= 13

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoopenvmtools: Update to 10.2.0
Michael Tremer [Thu, 11 Jan 2018 11:49:00 +0000 (11:49 +0000)] 
openvmtools: Update to 10.2.0

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agohaproxy: Update to version 1.8.0
Michael Tremer [Tue, 28 Nov 2017 17:13:59 +0000 (17:13 +0000)] 
haproxy: Update to version 1.8.0

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agostunnel: Update to 5.44
Michael Tremer [Tue, 28 Nov 2017 17:13:07 +0000 (17:13 +0000)] 
stunnel: Update to 5.44

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agonginx: Update to 1.13.7
Michael Tremer [Tue, 28 Nov 2017 16:53:01 +0000 (16:53 +0000)] 
nginx: Update to 1.13.7

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoswig: Update to 3.0.12
Michael Tremer [Tue, 28 Nov 2017 16:47:07 +0000 (16:47 +0000)] 
swig: Update to 3.0.12

Required to build recent versions of m2crypto.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopostfix: Update to 3.2.4
Michael Tremer [Tue, 28 Nov 2017 13:07:00 +0000 (13:07 +0000)] 
postfix: Update to 3.2.4

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoDrop libevent2-compat which doesn't build against OpenSSL 1.1
Michael Tremer [Sat, 25 Nov 2017 13:04:30 +0000 (13:04 +0000)] 
Drop libevent2-compat which doesn't build against OpenSSL 1.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship changed vpnmain.cgi
Michael Tremer [Wed, 31 Jan 2018 13:00:44 +0000 (13:00 +0000)] 
core118: Ship changed vpnmain.cgi

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agosyslogdctrl: Fix sed syntax issues
Michael Tremer [Tue, 30 Jan 2018 20:54:46 +0000 (20:54 +0000)] 
syslogdctrl: Fix sed syntax issues

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship changed ovpnmain.cgi
Michael Tremer [Tue, 30 Jan 2018 20:06:14 +0000 (20:06 +0000)] 
core118: Ship changed ovpnmain.cgi

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoremove dropped pakages to make sure that apache not miss php files.
Arne Fitzenreiter [Mon, 29 Jan 2018 18:44:17 +0000 (19:44 +0100)] 
remove dropped pakages to make sure that apache not miss php files.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 years agocore118: Ship forgotten menu file
Michael Tremer [Mon, 29 Jan 2018 17:29:11 +0000 (17:29 +0000)] 
core118: Ship forgotten menu file

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agofinish core118
Arne Fitzenreiter [Sat, 27 Jan 2018 18:13:14 +0000 (19:13 +0100)] 
finish core118

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 years agoclamav: Update to 0.99.3
Matthias Fischer [Fri, 26 Jan 2018 16:43:24 +0000 (17:43 +0100)] 
clamav: Update to 0.99.3

Excerpt from 'README':

"ClamAV 0.99.3 is a hotfix release to patch a set of vulnerabilities.

- fixes for the following CVE's: CVE-2017-6418, CVE-2017-6420,
  CVE-2017-12374, CVE-2017-12375, CVE-2017-12376, CVE-2017-12377,
  CVE-2017-12378, CVE-2017-12379, CVE-2017-12380.
- also included are 2 minor fixes to properly detect openssl install
  locations on FreeBSD 11, and prevent false warnings about zlib 1.2.1#
  version numbers."

For details see:
http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agolibvirt: update to version 4.0
Jonatan Schlag [Fri, 19 Jan 2018 18:29:03 +0000 (19:29 +0100)] 
libvirt: update to version 4.0

This version works for me. Some others do not ..

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopython3-libvirt: drop this package
Jonatan Schlag [Fri, 19 Jan 2018 18:29:02 +0000 (19:29 +0100)] 
python3-libvirt: drop this package

Since it is some work to update this package accordingly to the libvirt
version  and facing the fact that I know nobody who using this I suggest to drop this. If we
need this later we can just revert the commit.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoqemu: update to version 2.11
Jonatan Schlag [Fri, 19 Jan 2018 18:29:01 +0000 (19:29 +0100)] 
qemu: update to version 2.11

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agospice: update to version 0.14
Jonatan Schlag [Fri, 19 Jan 2018 18:29:00 +0000 (19:29 +0100)] 
spice: update to version 0.14

For changelog see:
https://cgit.freedesktop.org/spice/spice/tree/NEWS

This update alos fixes: CVE-2016-9577, CVE-2016-9578, CVE-2017-7506

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agospice-protocol: update to version 0.12.13
Jonatan Schlag [Fri, 19 Jan 2018 18:28:59 +0000 (19:28 +0100)] 
spice-protocol: update to version 0.12.13

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoopus: update to version 1.2.1
Jonatan Schlag [Fri, 19 Jan 2018 18:28:58 +0000 (19:28 +0100)] 
opus: update to version 1.2.1

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopyparsing: update to version 2.2.0
Jonatan Schlag [Fri, 19 Jan 2018 18:28:57 +0000 (19:28 +0100)] 
pyparsing: update to version 2.2.0

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoRevert "Add Intel microcode updates from Jan 2018"
Michael Tremer [Wed, 24 Jan 2018 16:08:22 +0000 (16:08 +0000)] 
Revert "Add Intel microcode updates from Jan 2018"

This reverts commit d404b1dba2a357e3683dbf62b95cefc41075c4ef.

Intel has pulled these microcode updates because of
random system reboots and systems becoming unstable.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoRevert "core118: Ship microcode updates for Intel processors"
Michael Tremer [Wed, 24 Jan 2018 16:07:58 +0000 (16:07 +0000)] 
Revert "core118: Ship microcode updates for Intel processors"

This reverts commit c015d425d177a18927f56cebd0d1b4d29a827d8b.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship updated wget
Michael Tremer [Wed, 24 Jan 2018 16:07:11 +0000 (16:07 +0000)] 
core118: Ship updated wget

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agowget: Update to 1.9.4
Matthias Fischer [Wed, 24 Jan 2018 07:32:24 +0000 (08:32 +0100)] 
wget: Update to 1.9.4

Excerpts from changelog (Details => http://git.savannah.gnu.org/cgit/wget.git):

"Switch off compression by default

Gzip compression has a number of bugs which need to be ironed out before we can support it
by default. Some of these stem from a misunderstanding of the HTTP spec, but a lot of them
are also due to many web servers not
being compliant with RFC 7231.

With this commit, I am marking GZip compression support as experimental
in GNU Wget pending further investigation and the addition of tests.

* src/http.c (gethttp): Fix bug that prevented all files from being decompressed

* src/host.c (sufmatch): Fix to domain matching

Replace HTTP urls with HTTPS where valid

Avoid redirecting output to file when tcgetpgrp fails
* src/log.c (check_redirect_output): tcgetpgrp can return -1 (ENOTTY),
be sure to check whether a valid controlling terminal exists before
redirecting. (Fixes: #51181)

Fix heap overflow in HTTP protocol handling (CVE-2017-13090)

Fix stack overflow in HTTP protocol handling (CVE-2017-13089)"

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agonano: Update to 2.9.2
Matthias Fischer [Wed, 24 Jan 2018 07:10:42 +0000 (08:10 +0100)] 
nano: Update to 2.9.2

For details see:
https://www.nano-editor.org/news.php

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship updated sed
Michael Tremer [Wed, 24 Jan 2018 16:06:32 +0000 (16:06 +0000)] 
core118: Ship updated sed

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agosed: Update to 4.4
Matthias Fischer [Tue, 23 Jan 2018 21:18:48 +0000 (22:18 +0100)] 
sed: Update to 4.4

Hi,

'sed' hasn't been updated in IPFire for a few years - I thought it could
be worthy an update:

Excerpt from 'NEWS':

"* Noteworthy changes in release 4.4 (2017-02-03) [stable]

  sed could segfault when invoked with specific combination of newlines
  in the input and regex pattern. [Bug introduced in sed-4.3]"

"Noteworthy changes" from release 4.2.2 to 4.3 can be found in 'NEWS' file, too much
to list them all...

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship LZ4
Michael Tremer [Tue, 23 Jan 2018 13:21:36 +0000 (13:21 +0000)] 
core118: Ship LZ4

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoLZ4: New compression library.
Erik Kapfer [Mon, 22 Jan 2018 18:04:59 +0000 (19:04 +0100)] 
LZ4: New compression library.

New lossless data compression algorithm.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship updated squid
Michael Tremer [Tue, 23 Jan 2018 13:09:37 +0000 (13:09 +0000)] 
core118: Ship updated squid

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agosquid 3.5.27: Patch for SA 2018:2
Matthias Fischer [Mon, 22 Jan 2018 16:49:52 +0000 (17:49 +0100)] 
squid 3.5.27: Patch for SA 2018:2

As announced, here is the second patch for 'squid 3.5.27'.

For details about this and the previous patch (2018_1) regarding "ESI Response
processing" and "HTTP message processing", see:

http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-announce-ADVISORY-SQUID-2018-1-Denial-of-Service-issue-in-ESI-Response-processing-tp4684618.html

http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-announce-ADVISORY-SQUID-2018-2-Denial-of-Service-issue-in-HTTP-Message-processing-td4684617.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agosquid 3.5.27: Patch for SA 2018:1
Matthias Fischer [Sat, 20 Jan 2018 17:50:51 +0000 (18:50 +0100)] 
squid 3.5.27: Patch for SA 2018:1

http://www.squid-cache.org/Versions/v3/3.5/changesets/

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agofirewall: Suppress warning about uninitialized array in GeoIP code
Michael Tremer [Mon, 22 Jan 2018 13:20:04 +0000 (13:20 +0000)] 
firewall: Suppress warning about uninitialized array in GeoIP code

Fixes #11597

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agopoppler is now linking against glib2
Michael Tremer [Mon, 22 Jan 2018 13:12:56 +0000 (13:12 +0000)] 
poppler is now linking against glib2

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoship updated CA bundle
Peter Müller [Thu, 18 Jan 2018 14:51:31 +0000 (15:51 +0100)] 
ship updated CA bundle

Add new generated CA bundle files to updater and remove
accidentally inserted blank line at the end of certdata.txt .

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoupdate ca-certificates CA bundle
Peter Müller [Thu, 18 Jan 2018 14:51:26 +0000 (15:51 +0100)] 
update ca-certificates CA bundle

Update the CA certificates list to what Mozilla NSS ships currently.

The original file can be retrieved from: https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship updated bind package
Michael Tremer [Sat, 20 Jan 2018 15:34:56 +0000 (15:34 +0000)] 
core118: Ship updated bind package

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agobind: Update to 9.11.2-P1
Matthias Fischer [Wed, 17 Jan 2018 23:16:30 +0000 (00:16 +0100)] 
bind: Update to 9.11.2-P1

Fixes CVE-2017-3145 (https://kb.isc.org/article/AA-01542)

For details see:
http://ftp.isc.org/isc/bind9/9.11.2-P1/RELEASE-NOTES-bind-9.11.2-P1.html

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agosyslogdctrl: Fix compiler error and SEGV
Michael Tremer [Sat, 20 Jan 2018 14:51:40 +0000 (14:51 +0000)] 
syslogdctrl: Fix compiler error and SEGV

Fixes #11574

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agoRevert "misc-progs: syslogdctrl: Fix data type of protocol variable"
Michael Tremer [Sat, 20 Jan 2018 14:45:10 +0000 (14:45 +0000)] 
Revert "misc-progs: syslogdctrl: Fix data type of protocol variable"

This reverts commit b269686f885757f5b251f04e50c3e87d2aebaf64.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 years agocore118: Ship updated unbound
Michael Tremer [Sat, 20 Jan 2018 14:38:56 +0000 (14:38 +0000)] 
core118: Ship updated unbound

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>