]> git.ipfire.org Git - people/teissler/ipfire-2.x.git/log
people/teissler/ipfire-2.x.git
11 years agostarted core59.
Arne Fitzenreiter [Mon, 9 Apr 2012 10:19:06 +0000 (12:19 +0200)] 
started core59.

11 years agofinished core59.
Arne Fitzenreiter [Sat, 12 May 2012 17:22:26 +0000 (19:22 +0200)] 
finished core59.

11 years agoGeoIP: update database to 01052012.
Arne Fitzenreiter [Sat, 12 May 2012 17:15:38 +0000 (19:15 +0200)] 
GeoIP: update database to 01052012.

11 years agodhcpcd: ignore MTU Smaller than 577.
Arne Fitzenreiter [Sat, 12 May 2012 15:13:45 +0000 (17:13 +0200)] 
dhcpcd: ignore MTU Smaller than 577.

Normally 576 is the smallest valid mtu but some cable provider set this
also if they support much higher mtu's. Fedora does not accept
this to prevent speed problems with such isp connections so we do the same.
If you really need mtu=576 you can still force at at the setup.

11 years agophp: security update to 5.3.13 (CVE-2012-2311).
Arne Fitzenreiter [Sat, 12 May 2012 13:33:42 +0000 (15:33 +0200)] 
php: security update to 5.3.13 (CVE-2012-2311).

11 years agoopenssh: update to 6.0p1.
Arne Fitzenreiter [Sat, 12 May 2012 13:32:47 +0000 (15:32 +0200)] 
openssh: update to 6.0p1.

11 years agoopenssl: security update to 0.9.8x (CVE-2012-2333).
Arne Fitzenreiter [Sat, 12 May 2012 13:30:38 +0000 (15:30 +0200)] 
openssl: security update to 0.9.8x (CVE-2012-2333).

Invalid TLS/DTLS record attack (CVE-2012-2333)
===============================================

A flaw in the OpenSSL handling of CBC mode ciphersuites in TLS 1.1, 1.2 and
DTLS can be exploited in a denial of service attack on both clients and
servers.

DTLS applications are affected in all versions of OpenSSL. TLS is only
affected in OpenSSL 1.0.1 and later.

Thanks to Codenomicon for discovering this issue using Fuzz-o-Matic fuzzing
as a service testing platform.

The fix was developed by Stephen Henson of the OpenSSL core team.

Affected users should upgrade to OpenSSL 1.0.1c, 1.0.0j or 0.9.8x

References
==========

URL for this Security Advisory:
http://www.openssl.org/news/secadv_20120510.txt

11 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Sun, 6 May 2012 10:54:13 +0000 (12:54 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

11 years agotraceroute: update to 2.0.18 and fix name resolution.
Arne Fitzenreiter [Sun, 6 May 2012 10:51:14 +0000 (12:51 +0200)] 
traceroute: update to 2.0.18 and fix name resolution.

fixes #10097

11 years agostrongswan: update to 4.6.3.
Arne Fitzenreiter [Sat, 5 May 2012 21:25:07 +0000 (23:25 +0200)] 
strongswan: update to 4.6.3.

11 years agopython: update to 2.7.3.
Arne Fitzenreiter [Sat, 5 May 2012 21:23:53 +0000 (23:23 +0200)] 
python: update to 2.7.3.

11 years agofix core58 merge problem.
Arne Fitzenreiter [Sat, 5 May 2012 21:21:18 +0000 (23:21 +0200)] 
fix core58 merge problem.

11 years agocore59: add openssl to core update.
Arne Fitzenreiter [Sat, 5 May 2012 21:19:36 +0000 (23:19 +0200)] 
core59: add openssl to core update.

11 years agoopenssl: security update to 0.9.8w. (CVE-2012-2131).
Arne Fitzenreiter [Wed, 2 May 2012 17:42:02 +0000 (19:42 +0200)] 
openssl: security update to 0.9.8w. (CVE-2012-2131).

SN1 BIO incomplete fix (CVE-2012-2131)
=======================================

It was discovered that the fix for CVE-2012-2110 released on 19 Apr
2012 was not sufficient to correct the issue for OpenSSL 0.9.8.

Please see http://www.openssl.org/news/secadv_20120419.txt for details
of that vulnerability.

This issue only affects OpenSSL 0.9.8v.  OpenSSL 1.0.1a and 1.0.0i
already contain a patch sufficient to correct CVE-2012-2110.

Thanks to Red Hat for discovering and fixing this issue.

Affected users should upgrade to 0.9.8w.

References
==========

URL for this Security Advisory:
http://www.openssl.org/news/secadv_20120424.txt

11 years agoMerge branch 'master' into next
Arne Fitzenreiter [Wed, 2 May 2012 14:55:26 +0000 (16:55 +0200)] 
Merge branch 'master' into next

11 years agosamba: security update to 3.5.15. (CVE-2012-2111).
Arne Fitzenreiter [Wed, 2 May 2012 08:10:07 +0000 (10:10 +0200)] 
samba: security update to 3.5.15. (CVE-2012-2111).

This security release addresses CVE-2012-2111 (incorrect permission checks when
granting/removing privileges could compromise file server security).

12 years agosamba: security update to 3.5.14. (CVE-2012-1182).
Arne Fitzenreiter [Tue, 10 Apr 2012 18:21:37 +0000 (20:21 +0200)] 
samba: security update to 3.5.14. (CVE-2012-1182).

Further information can be found in the security advisory:
http://www.samba.org/samba/security/CVE-2012-1182

12 years agostarted core59.
Arne Fitzenreiter [Mon, 9 Apr 2012 10:19:06 +0000 (12:19 +0200)] 
started core59.

12 years agoMerge branch 'master' into next
Arne Fitzenreiter [Mon, 9 Apr 2012 10:15:59 +0000 (12:15 +0200)] 
Merge branch 'master' into next

Conflicts:
config/rootfiles/core/58/filelists/files
make.sh

12 years agofinished core58.
Arne Fitzenreiter [Sat, 7 Apr 2012 09:39:23 +0000 (11:39 +0200)] 
finished core58.

12 years agohwdata: updata usb and pci ids database.
Arne Fitzenreiter [Fri, 6 Apr 2012 17:30:24 +0000 (19:30 +0200)] 
hwdata: updata usb and pci ids database.

12 years agoGeoIP: update database to 03032012.
Arne Fitzenreiter [Fri, 6 Apr 2012 17:22:23 +0000 (19:22 +0200)] 
GeoIP: update database to 03032012.

12 years agocore58: add cryptodev module to updater.
Arne Fitzenreiter [Fri, 6 Apr 2012 16:49:20 +0000 (18:49 +0200)] 
core58: add cryptodev module to updater.

12 years agocryptodev: update to 1.4.
Arne Fitzenreiter [Sat, 31 Mar 2012 09:21:15 +0000 (11:21 +0200)] 
cryptodev: update to 1.4.

12 years agoopenssl: fix aes accleration via cryptodev.
Arne Fitzenreiter [Sat, 31 Mar 2012 09:20:27 +0000 (11:20 +0200)] 
openssl: fix aes accleration via cryptodev.

12 years agopound: Add patch to select certificates by their SANs.
Michael Tremer [Fri, 6 Apr 2012 11:42:27 +0000 (13:42 +0200)] 
pound: Add patch to select certificates by their SANs.

http://www.apsis.ch/pound/pound_list/archive/2012/2012-02/1329442080000#1329442080000

12 years agoclamav: updated to 0.97.4.
Arne Fitzenreiter [Sun, 18 Mar 2012 12:14:59 +0000 (13:14 +0100)] 
clamav: updated to 0.97.4.

12 years agoopenssl: update to 0.9.8u.
Arne Fitzenreiter [Tue, 13 Mar 2012 20:16:25 +0000 (21:16 +0100)] 
openssl: update to 0.9.8u.

12 years agosamba: update to 3.5.13.
Arne Fitzenreiter [Tue, 13 Mar 2012 19:47:09 +0000 (20:47 +0100)] 
samba: update to 3.5.13.

12 years agogit: Update to 1.7.9.3.
Michael Tremer [Sun, 11 Mar 2012 15:53:32 +0000 (16:53 +0100)] 
git: Update to 1.7.9.3.

12 years agofireinfo: Update to 2.1.4.
Michael Tremer [Sun, 11 Mar 2012 13:50:44 +0000 (14:50 +0100)] 
fireinfo: Update to 2.1.4.

Fixes an issue with the detection of online CPUs on ARM.

12 years agousb_modeswitch: update to 1.2.3.
Arne Fitzenreiter [Sat, 10 Mar 2012 16:37:23 +0000 (17:37 +0100)] 
usb_modeswitch: update to 1.2.3.

12 years agostrongswan: update to 4.6.2.
Arne Fitzenreiter [Sat, 10 Mar 2012 16:32:31 +0000 (17:32 +0100)] 
strongswan: update to 4.6.2.

fixes #10037

12 years agoAdd libpng update to core update 58.
Michael Tremer [Tue, 6 Mar 2012 21:26:22 +0000 (22:26 +0100)] 
Add libpng update to core update 58.

12 years agolibpng: Update to 1.2.46.
Michael Tremer [Sat, 4 Feb 2012 10:17:22 +0000 (11:17 +0100)] 
libpng: Update to 1.2.46.

Fixes several security issues from 2011.

12 years agoOpen core update 58 and import changes that were already commited.
Michael Tremer [Tue, 6 Mar 2012 21:23:29 +0000 (22:23 +0100)] 
Open core update 58 and import changes that were already commited.

12 years agoopenvpn: Update to 2.2.2.
Michael Tremer [Sat, 25 Feb 2012 11:10:25 +0000 (12:10 +0100)] 
openvpn: Update to 2.2.2.

Add --enable-password-save switch that was requested by the
community.

See bug #10036.

12 years agovim: Add "set ruler" option to configuration file.
Michael Tremer [Wed, 22 Feb 2012 23:01:05 +0000 (00:01 +0100)] 
vim: Add "set ruler" option to configuration file.

This will show a small line at the bottom which displays
the current cursor position and more.

References bug #10021.

12 years agocore57: stop/start ipsec at update.
Arne Fitzenreiter [Sun, 19 Feb 2012 12:04:06 +0000 (13:04 +0100)] 
core57: stop/start ipsec at update.

12 years agohwdata: updata usb and pci ids database.
Arne Fitzenreiter [Fri, 6 Apr 2012 17:30:24 +0000 (19:30 +0200)] 
hwdata: updata usb and pci ids database.

12 years agoGeoIP: update database to 03032012.
Arne Fitzenreiter [Fri, 6 Apr 2012 17:22:23 +0000 (19:22 +0200)] 
GeoIP: update database to 03032012.

12 years agocore58: add cryptodev module to updater.
Arne Fitzenreiter [Fri, 6 Apr 2012 16:49:20 +0000 (18:49 +0200)] 
core58: add cryptodev module to updater.

12 years agocryptodev: update to 1.4.
Arne Fitzenreiter [Sat, 31 Mar 2012 09:21:15 +0000 (11:21 +0200)] 
cryptodev: update to 1.4.

12 years agoopenssl: fix aes accleration via cryptodev.
Arne Fitzenreiter [Sat, 31 Mar 2012 09:20:27 +0000 (11:20 +0200)] 
openssl: fix aes accleration via cryptodev.

12 years agopound: Add patch to select certificates by their SANs.
Michael Tremer [Fri, 6 Apr 2012 11:42:27 +0000 (13:42 +0200)] 
pound: Add patch to select certificates by their SANs.

http://www.apsis.ch/pound/pound_list/archive/2012/2012-02/1329442080000#1329442080000

12 years agoclamav: updated to 0.97.4.
Arne Fitzenreiter [Sun, 18 Mar 2012 12:14:59 +0000 (13:14 +0100)] 
clamav: updated to 0.97.4.

12 years agoopenssl: update to 0.9.8u.
Arne Fitzenreiter [Tue, 13 Mar 2012 20:16:25 +0000 (21:16 +0100)] 
openssl: update to 0.9.8u.

12 years agosamba: update to 3.5.13.
Arne Fitzenreiter [Tue, 13 Mar 2012 19:47:09 +0000 (20:47 +0100)] 
samba: update to 3.5.13.

12 years agoAdd VPN changes to core update.
Michael Tremer [Mon, 12 Mar 2012 10:13:51 +0000 (11:13 +0100)] 
Add VPN changes to core update.

12 years agogit: Update to 1.7.9.3.
Michael Tremer [Sun, 11 Mar 2012 15:53:32 +0000 (16:53 +0100)] 
git: Update to 1.7.9.3.

12 years agofireinfo: Update to 2.1.4.
Michael Tremer [Sun, 11 Mar 2012 13:50:44 +0000 (14:50 +0100)] 
fireinfo: Update to 2.1.4.

Fixes an issue with the detection of online CPUs on ARM.

12 years agousb_modeswitch: update to 1.2.3.
Arne Fitzenreiter [Sat, 10 Mar 2012 16:37:23 +0000 (17:37 +0100)] 
usb_modeswitch: update to 1.2.3.

12 years agostrongswan: update to 4.6.2.
Arne Fitzenreiter [Sat, 10 Mar 2012 16:32:31 +0000 (17:32 +0100)] 
strongswan: update to 4.6.2.

fixes #10037

12 years agoImport VPN changes by the Special Interest Group.
Michael Tremer [Tue, 6 Mar 2012 21:53:07 +0000 (22:53 +0100)] 
Import VPN changes by the Special Interest Group.

See here for more details:
  http://lists.ipfire.org/pipermail/sig-vpn/2012-March/000031.html

12 years agoAdd libpng update to core update 58.
Michael Tremer [Tue, 6 Mar 2012 21:26:22 +0000 (22:26 +0100)] 
Add libpng update to core update 58.

12 years agoMerge branch 'libpng-update' into next
Michael Tremer [Tue, 6 Mar 2012 21:24:28 +0000 (22:24 +0100)] 
Merge branch 'libpng-update' into next

12 years agoOpen core update 58 and import changes that were already commited.
Michael Tremer [Tue, 6 Mar 2012 21:23:29 +0000 (22:23 +0100)] 
Open core update 58 and import changes that were already commited.

12 years agoopenvpn: Update to 2.2.2.
Michael Tremer [Sat, 25 Feb 2012 11:10:25 +0000 (12:10 +0100)] 
openvpn: Update to 2.2.2.

Add --enable-password-save switch that was requested by the
community.

See bug #10036.

12 years agovim: Add "set ruler" option to configuration file.
Michael Tremer [Wed, 22 Feb 2012 23:01:05 +0000 (00:01 +0100)] 
vim: Add "set ruler" option to configuration file.

This will show a small line at the bottom which displays
the current cursor position and more.

References bug #10021.

12 years agocore57: stop/start ipsec at update.
Arne Fitzenreiter [Sun, 19 Feb 2012 12:04:06 +0000 (13:04 +0100)] 
core57: stop/start ipsec at update.

12 years agofinished core57.
Arne Fitzenreiter [Sun, 19 Feb 2012 11:51:12 +0000 (12:51 +0100)] 
finished core57.

12 years agonetwork: don't set ip address "1.1.1.1".
Arne Fitzenreiter [Sun, 19 Feb 2012 11:48:42 +0000 (12:48 +0100)] 
network: don't set ip address "1.1.1.1".

This change made also green-only with dhcp possible.
configure green to 1.1.1.1 and red to dhcp client and RED_DEV=green0.

12 years agopound: update to latest stable 2.6
Dirk Wagner [Sat, 11 Feb 2012 17:28:13 +0000 (18:28 +0100)] 
pound: update to latest stable 2.6

12 years agopound: update to latest stable 2.6
Dirk Wagner [Sat, 11 Feb 2012 17:27:13 +0000 (18:27 +0100)] 
pound: update to latest stable 2.6

12 years agonut: fixed wrong version in filename
Dirk Wagner [Fri, 10 Feb 2012 21:23:44 +0000 (22:23 +0100)] 
nut: fixed wrong version in filename

12 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Dirk Wagner [Fri, 10 Feb 2012 19:46:44 +0000 (20:46 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

12 years agonut: update to latest version 2.6.3
Dirk Wagner [Fri, 10 Feb 2012 19:44:14 +0000 (20:44 +0100)] 
nut: update to latest version 2.6.3

12 years agooutgoingfw.cgi: Fix enabled checkbox when editing rules.
Michael Tremer [Fri, 10 Feb 2012 10:10:14 +0000 (11:10 +0100)] 
outgoingfw.cgi: Fix enabled checkbox when editing rules.

When a rule was edited, the enabled checkbox was always unchecked.

References bug #10022.

12 years agostrongswan: Customize the welcome banner.
Michael Tremer [Fri, 10 Feb 2012 10:01:42 +0000 (11:01 +0100)] 
strongswan: Customize the welcome banner.

References:
 http://forum.ipfire.org/index.php/topic,5993.0.html
 http://forum.ipfire.org/index.php/topic,3329.0.html

12 years agoinstaller: Enhance mountsource.sh script.
Michael Tremer [Wed, 8 Feb 2012 21:37:09 +0000 (22:37 +0100)] 
installer: Enhance mountsource.sh script.

Searches for installation images on all partitions on external
media.

References bug #10020.

12 years agovim: Create configuration files for better usage.
Michael Tremer [Wed, 8 Feb 2012 21:35:30 +0000 (22:35 +0100)] 
vim: Create configuration files for better usage.

This commits also ships all syntax highlighting information
and among others in /usr/share/vim.

References bug #10021.

12 years agoMerge branch 'master' into next
Michael Tremer [Wed, 8 Feb 2012 20:54:26 +0000 (21:54 +0100)] 
Merge branch 'master' into next

12 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Wed, 8 Feb 2012 20:47:09 +0000 (21:47 +0100)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

12 years agoRemove donation button from credits.cgi.
Michael Tremer [Wed, 8 Feb 2012 20:39:26 +0000 (21:39 +0100)] 
Remove donation button from credits.cgi.

12 years agoapache: fix typo.
Arne Fitzenreiter [Wed, 8 Feb 2012 18:59:36 +0000 (19:59 +0100)] 
apache: fix typo.

12 years agocups: update to 1.4.8.
Arne Fitzenreiter [Wed, 8 Feb 2012 06:50:17 +0000 (07:50 +0100)] 
cups: update to 1.4.8.

12 years agocore57: add apache and squid to updater.
Arne Fitzenreiter [Wed, 8 Feb 2012 06:49:48 +0000 (07:49 +0100)] 
core57: add apache and squid to updater.

12 years agosquid: update to 3.19.
Arne Fitzenreiter [Wed, 8 Feb 2012 06:48:52 +0000 (07:48 +0100)] 
squid: update to 3.19.

12 years agoapache: security update to 2.2.22.
Arne Fitzenreiter [Wed, 8 Feb 2012 06:43:48 +0000 (07:43 +0100)] 
apache: security update to 2.2.22.

Fix six low and moderate security flaws. Most of them are not important for ipfire.
low: mod_setenvif .htaccess privilege escalation CVE-2011-3607
low: mod_log_config crash CVE-2012-0021
low: scoreboard parent DoS CVE-2012-0031
moderate: mod_proxy reverse proxy exposure CVE-2011-4317
moderate: error responses can expose cookies CVE-2012-0053
moderate: mod_proxy reverse proxy exposure CVE-2011-3368

For details check: http://httpd.apache.org/security/vulnerabilities_22.html

12 years agocore57: add php update to updater.
Arne Fitzenreiter [Sun, 5 Feb 2012 18:11:17 +0000 (19:11 +0100)] 
core57: add php update to updater.

12 years agophp: security update to 5.3.10.
Arne Fitzenreiter [Sun, 5 Feb 2012 18:05:18 +0000 (19:05 +0100)] 
php: security update to 5.3.10.

5.3.10 Fixes arbitary remote code execution CVE-2012-0830
5.3.9 Fixes for CVE-2011-4566 and CVE-2011-4885
...

12 years agostarted core57.
Arne Fitzenreiter [Sun, 5 Feb 2012 15:49:37 +0000 (16:49 +0100)] 
started core57.

12 years agocore56: add static-rules startfiles to updater.
Arne Fitzenreiter [Sun, 5 Feb 2012 15:46:57 +0000 (16:46 +0100)] 
core56: add static-rules startfiles to updater.

12 years agolibpng: Update to 1.2.46.
Michael Tremer [Sat, 4 Feb 2012 10:17:22 +0000 (11:17 +0100)] 
libpng: Update to 1.2.46.

Fixes several security issues from 2011.

12 years agocore56: don't reset ssh/ssl config at update.
Arne Fitzenreiter [Sat, 28 Jan 2012 11:26:03 +0000 (12:26 +0100)] 
core56: don't reset ssh/ssl config at update.

12 years agofs-resize: answer yes at fsck to continue at last mount in future.
Arne Fitzenreiter [Fri, 27 Jan 2012 08:22:15 +0000 (09:22 +0100)] 
fs-resize: answer yes at fsck to continue at last mount in future.

12 years agoMerge branch 'master' into core56
Arne Fitzenreiter [Thu, 26 Jan 2012 16:46:56 +0000 (17:46 +0100)] 
Merge branch 'master' into core56

12 years agofinish core56.
Arne Fitzenreiter [Thu, 26 Jan 2012 16:43:59 +0000 (17:43 +0100)] 
finish core56.

12 years agoinitscripts: rootfile update.
Arne Fitzenreiter [Thu, 26 Jan 2012 16:39:00 +0000 (17:39 +0100)] 
initscripts: rootfile update.

12 years agoMerge commit 'origin/static-routes'
Arne Fitzenreiter [Tue, 24 Jan 2012 20:44:16 +0000 (21:44 +0100)] 
Merge commit 'origin/static-routes'

12 years agoMerge commit 'origin/next'
Arne Fitzenreiter [Tue, 24 Jan 2012 19:53:06 +0000 (20:53 +0100)] 
Merge commit 'origin/next'

12 years agoflash-images: activate autoresize also on arm.
Arne Fitzenreiter [Tue, 24 Jan 2012 17:17:14 +0000 (18:17 +0100)] 
flash-images: activate autoresize also on arm.

12 years agoReload static routes after a connecting to the internet.
Michael Tremer [Mon, 23 Jan 2012 21:32:32 +0000 (22:32 +0100)] 
Reload static routes after a connecting to the internet.

BUg 10007. Some users claimed, that not all static routes are
set up correctly at boot time.

12 years agoAllow : character in configuration files.
Michael Tremer [Mon, 23 Jan 2012 21:09:31 +0000 (22:09 +0100)] 
Allow : character in configuration files.

According to bug #10006, it is needed in some DSL credentials.

As : is not a special character in shell code (at least if
{} is not allowed either) we can safely use it.

12 years agoflash-images: increase size of root partition.
Arne Fitzenreiter [Sun, 22 Jan 2012 09:57:35 +0000 (10:57 +0100)] 
flash-images: increase size of root partition.

Minimal media-size is now 2GB.

12 years agocore56: stop/start sshd and apache while updateing.
Arne Fitzenreiter [Sat, 21 Jan 2012 19:26:26 +0000 (20:26 +0100)] 
core56: stop/start sshd and apache while updateing.

12 years agocore56: add openvpnctrl to updater.
Arne Fitzenreiter [Sat, 21 Jan 2012 19:24:09 +0000 (20:24 +0100)] 
core56: add openvpnctrl to updater.

12 years agoinitskripts: add disc sync before unmounting filesystems.
Arne Fitzenreiter [Sat, 21 Jan 2012 19:20:57 +0000 (20:20 +0100)] 
initskripts: add disc sync before unmounting filesystems.

12 years agocore56: add Crypt-PasswdMD5 to updater.
Arne Fitzenreiter [Sat, 21 Jan 2012 19:19:25 +0000 (20:19 +0100)] 
core56: add Crypt-PasswdMD5 to updater.

12 years agochpasswd.cgi: fixed for new MD5 password hashes.
Arne Fitzenreiter [Sat, 21 Jan 2012 19:13:54 +0000 (20:13 +0100)] 
chpasswd.cgi: fixed for new MD5 password hashes.