Christian Schoenebeck [Sun, 7 Feb 2016 20:52:02 +0000 (21:52 +0100)]
privoxy: bump to version 3.0.24
* upstream to Privoxy 3.0.24
* add facility to set compile options
* add file list to be saved on sysupgrade
* fixed PKG_MAINTAINER string
* add port 8118 used by privoxy to /etc/services
* new "boot_delay" option (default 10 seconds) to wait for interfaces to come up before hotplug restarts are enabled
Signed-off-by: Christian Schoenebeck <christian.schoenebeck@gmail.com>
Hannu Nyman [Sun, 7 Feb 2016 17:29:22 +0000 (19:29 +0200)]
Merge pull request #2356 from damianorenfer/master
net/dnscrypt-proxy: update 1.6.1, security update
Damiano Renfer [Sun, 7 Feb 2016 17:22:26 +0000 (18:22 +0100)]
net/dnscrypt-proxy: update 1.6.1, security update see https://github.com/jedisct1/dnscrypt-proxy/releases/tag/1.6.1
Signed-off-by: Damiano Renfer damiano.renfer@gmail.com
Hannu Nyman [Sun, 7 Feb 2016 10:51:54 +0000 (12:51 +0200)]
Merge pull request #2352 from chris5560/radicale
Radicale: bump to version 1.1.1
Hannu Nyman [Sun, 7 Feb 2016 09:05:12 +0000 (11:05 +0200)]
Merge pull request #2351 from chris5560/ddns-scripts
ddns-scripts: update to 2.6.1-1 with several fixes
Michael Heimpold [Sat, 6 Feb 2016 22:26:07 +0000 (23:26 +0100)]
php5: update to 5.6.18
Note: Upstream tagged this as security release.
Signed-off-by: Michael Heimpold <mhei@heimpold.de>
Christian Schoenebeck [Sat, 6 Feb 2016 16:09:26 +0000 (17:09 +0100)]
Radicale: bump to version 1.1.1
* upstream to Radicale 1.1.1
* add file list to be saved on sysupgrade
Signed-off-by: Christian Schoenebeck <christian.schoenebeck@gmail.com>
Christian Schoenebeck [Sat, 6 Feb 2016 14:48:39 +0000 (15:48 +0100)]
ddns-scripts: update to 2.6.1-1 with several fixes
- new function expand_ipv6()
- expand IPv6 before compare https://dev.openwrt.org/ticket/21725
- Fix split_FQDN() to return host.subdomain correctly #2334
- modified check for musl library used by nslookup #2341 #2346 thanks to Arjen de Korte
Signed-off-by: Christian Schoenebeck <christian.schoenebeck@gmail.com>
Hannu Nyman [Wed, 3 Feb 2016 18:40:08 +0000 (20:40 +0200)]
Merge pull request #2344 from dibdot/adblock
adblock: 0.60.1
Dirk Brenken [Wed, 3 Feb 2016 18:19:29 +0000 (19:19 +0100)]
adblock: 0.60.1
- fix possible race condition during startup
- fix duplicate logging during startup
- fix wget parms to prevent partitial downloads
- fix iptables rules to meet openwrt user chains
- added a rule in output chain to reject local ad related requests as
well
- changed default IPv4/IPv6 blackhole ip address to fix routing issues
with windows clients
Signed-off-by: Dirk Brenken <openwrt@brenken.org>
Nikos Mavrogiannopoulos [Wed, 3 Feb 2016 08:56:54 +0000 (09:56 +0100)]
gnutls: updated to 3.4.9
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
tripolar [Wed, 3 Feb 2016 00:01:23 +0000 (01:01 +0100)]
Merge pull request #2339 from diizzyy/patch-1
nfs-kernel-server: use libevent2, update copyright and bump PKG_RELEASE
diizzyy [Tue, 2 Feb 2016 04:32:42 +0000 (05:32 +0100)]
nfs-kernel-server: use libevent2, update copyright and bump PKG_RELEASE
Use libevent2 instead of libevent
Update copyright to 2016
Bump PKG_RELEASE due to package changes
Signed-off-by: Daniel Engberg <daniel.engberg.lists@pyret.net>
Ted Hess [Mon, 1 Feb 2016 20:56:57 +0000 (15:56 -0500)]
Merge pull request #2336 from diizzyy/patch-1
exfat-nofuse: update version
diizzyy [Mon, 1 Feb 2016 11:17:47 +0000 (12:17 +0100)]
exfat-nofuse: update version
Fixes filesystem corruption reports after writing on Linux and running chkdsk afterwards on Windows.
Signed-off-by: Daniel Engberg <daniel.engberg.lists@pyret.net>
Hannu Nyman [Mon, 1 Feb 2016 09:16:11 +0000 (11:16 +0200)]
Merge pull request #2333 from dubek/rsyslog-8.16.0
net/rsyslog: update to 8.16.0
Dov Murik [Mon, 1 Feb 2016 01:50:26 +0000 (20:50 -0500)]
net/rsyslog: update to 8.16.0
Signed-off-by: Dov Murik <dmurik@us.ibm.com>
Florian Fainelli [Sun, 31 Jan 2016 03:27:16 +0000 (19:27 -0800)]
Merge pull request #2326 from ffainelli/iptraf
net: Add iptraf-ng
Yousong Zhou [Sat, 30 Jan 2016 18:15:04 +0000 (02:15 +0800)]
Merge pull request #2316 from yunfan/master
dvtm: initial version 0.15
Luka Perkov [Fri, 29 Jan 2016 17:04:34 +0000 (18:04 +0100)]
Merge pull request #2264 from dangowrt/squid-libcom_err-builddep
squid: build-depend on libext2fs
Luka Perkov [Fri, 29 Jan 2016 17:00:48 +0000 (18:00 +0100)]
Merge pull request #2321 from karlp/pulls/file-typos
libs: file: fix typo in default call
yunfan [Tue, 26 Jan 2016 14:24:02 +0000 (22:24 +0800)]
dvtm: initial version 0.15
Signed-off-by: Yunfan Jiang <jyf1987@gmail.com>
Florian Fainelli [Thu, 28 Jan 2016 22:24:17 +0000 (14:24 -0800)]
Merge pull request #2324 from ffainelli/bonnieplus
utils: Import bonnie++
Florian Fainelli [Thu, 28 Jan 2016 22:18:14 +0000 (14:18 -0800)]
net: Add iptraf-ng
Add iptraf-ng 1.1.4 which is the successor of iptraf. Tested on
the realview target.
Signed-off-by: Florian Fainelli <florian@openwrt.org>
Hannu Nyman [Thu, 28 Jan 2016 18:07:01 +0000 (20:07 +0200)]
Merge pull request #2325 from Wedmer/master
[utils/zoneinfo] Updated to the latest release version
Michael Heimpold [Thu, 28 Jan 2016 16:29:55 +0000 (17:29 +0100)]
Merge pull request #2317 from mhei/fix-automake
automake: fix unversioned links during package build
Vladimir Ulrich [Thu, 28 Jan 2016 16:23:31 +0000 (19:23 +0300)]
[utils/zoneinfo] Updated to the latest release version
Signed-off-by: Vladimir Ulrich <admin@evl.su>
Florian Fainelli [Wed, 27 Jan 2016 20:44:44 +0000 (12:44 -0800)]
utils: Import bonnie++
Import bonnie++ from oldpackages:
* update to 1.97
* refresh patches
* add license tags
* add myself as maintainer
Signed-off-by: Florian Fainelli <florian@openwrt.org>
Karl Palsson [Wed, 27 Jan 2016 11:14:16 +0000 (11:14 +0000)]
libs: file: fix typo in default call
Corrects the display and help text for file and libmagic in menuconfig.
Signed-off-by: Karl Palsson <karlp@remake.is>
Michael Heimpold [Tue, 26 Jan 2016 20:48:50 +0000 (21:48 +0100)]
automake: fix unversioned links during package build
Reported by buildbots (shortened and line-wrapped):
...
ln -sf -r .../ipkg-ramips_24kec/automake/usr/bin/automake-1.15
.../ipkg-ramips_24kec/automake/usr/bin/automake
ln: invalid option -- 'r'
Signed-off-by: Michael Heimpold <mhei@heimpold.de>
Thomas Heil [Tue, 26 Jan 2016 13:04:00 +0000 (14:04 +0100)]
Merge pull request #2273 from xypron/apr
libs/apr: use @APACHE download facility
Thomas Heil [Tue, 26 Jan 2016 13:03:44 +0000 (14:03 +0100)]
Merge pull request #2274 from xypron/apr-util
libs/apr-util: use @APACHE download facility
Thomas Heil [Tue, 26 Jan 2016 13:02:59 +0000 (14:02 +0100)]
Merge pull request #2275 from xypron/apache
net/apache: use @APACHE download facility
Hannu Nyman [Tue, 26 Jan 2016 10:17:02 +0000 (12:17 +0200)]
Merge pull request #2304 from dibdot/adblock
adblock: update to 0.60.0
Hannu Nyman [Tue, 26 Jan 2016 08:39:03 +0000 (10:39 +0200)]
Merge pull request #2310 from chris5560/master
ddns-scripts: Ver.2.6.0 - support hostip and uclient-fetch
Hannu Nyman [Tue, 26 Jan 2016 08:30:59 +0000 (10:30 +0200)]
Merge pull request #2306 from mlichvar/chrony-update-2.2.1
chrony: update to 2.2.1
Hannu Nyman [Tue, 26 Jan 2016 07:17:43 +0000 (09:17 +0200)]
Merge pull request #2282 from commodo/python3-setuptools-upgrade
python3-setuptools: upgrade to version 19.4
Hannu Nyman [Tue, 26 Jan 2016 07:17:22 +0000 (09:17 +0200)]
Merge pull request #2281 from commodo/python-setuptools-upgrade
python-setuptools: upgrade to version 19.4
Peter Wagner [Mon, 25 Jan 2016 19:25:47 +0000 (20:25 +0100)]
ntpd: update to 4.2.8p6
Signed-off-by: Peter Wagner <tripolar@gmx.at>
Dirk Brenken [Sat, 23 Jan 2016 21:54:01 +0000 (22:54 +0100)]
adblock: update to 0.60.0
* "zero-conf" installation & setup, usually no manual config changes
required (i.e. ip address, network devices etc.)
* full IPv4 and IPv6 support
* new adblock list source (malwaredomainlist.com)
* adblock related statistics will be done by iptables
* removed curl dependency
* for IPv6 support you need 'kmod-ipt-nat6'
* fix Chaos Calmer compability
* various small changes & fixes
* updated documentation
* updated maintainer email address
Signed-off-by: Dirk Brenken <dirk@brenken.org>
heil [Mon, 25 Jan 2016 16:00:31 +0000 (17:00 +0100)]
haproxy: add pending patches from upstream
- [PATCH 11/13] BUG/MEDIUM: peers: table entries learned from a remote
- [PATCH 12/13] BUG/MEDIUM: peers: old stick table updates could be
- [PATCH 13/13] CLEANUP: haproxy: using _GNU_SOURCE instead of
Signed-off-by: heil <heil@terminal-consulting.de>
heil [Mon, 25 Jan 2016 15:57:07 +0000 (16:57 +0100)]
nginx: add naxsi module
- this brings back naxsi support aka WAF for nginx
Signed-off-by: heil <heil@terminal-consulting.de>
Dirk Feytons [Thu, 10 Dec 2015 15:24:00 +0000 (16:24 +0100)]
nginx: upstep to 1.9.9
Signed-off-by: Dirk Feytons <dirk.feytons@gmail.com>
Karl Palsson [Mon, 25 Jan 2016 13:40:15 +0000 (13:40 +0000)]
libwebsockets: bump to v1.6.2
Many user api changes, largely to cleanup and make more consistent.
Full changelog available at
http://git.libwebsockets.org/cgi-bin/cgit/libwebsockets/tree/changelog
Signed-off-by: Karl Palsson <karlp@remake.is>
Karl Palsson [Mon, 25 Jan 2016 13:33:21 +0000 (13:33 +0000)]
libwebsockets: Correctly enable IPv6 support
Signed-off-by: Karl Palsson <karlp@remake.is>
heil [Mon, 25 Jan 2016 13:06:18 +0000 (14:06 +0100)]
unixodbc:
- corect fetch url
Signed-off-by: heil <heil@terminal-consulting.de>
heil [Mon, 25 Jan 2016 13:05:02 +0000 (14:05 +0100)]
pcre: upgrade to 0.8.38
fixes:
* CVE 2015-2327 CVE 2015-2328 CVE 2015-8380 CVE 2015-8381 CVE
* 2015-8382
* CVE 2015-8383 CVE 2015-8384 CVE 2015-8385 CVE 2015-8386 CVE
* 2015-8387
* CVE 2015-8388 CVE 2015-8389 CVE 2015-8390 CVE 2015-8391 CVE
* 2015-8392
* CVE 2015-8393 CVE 2015-8394 CVE 2015-8395
Signed-off-by: heil <heil@terminal-consulting.de>
heil [Mon, 25 Jan 2016 12:29:55 +0000 (13:29 +0100)]
prosody: upgrade to 0.9.9
fixes:
* path traversal vulnerability in mod_http_files (CVE-2016-1231)
* use of weak PRNG in generation of dialback secrets (CVE-2016-1232)
Signed-off-by: heil <heil@terminal-consulting.de>
Michael Heimpold [Sun, 24 Jan 2016 20:33:25 +0000 (21:33 +0100)]
u2pnpd: update to 0.3
Signed-off-by: Michael Heimpold <mhei@heimpold.de>
Michael Heimpold [Sun, 24 Jan 2016 19:39:25 +0000 (20:39 +0100)]
Merge pull request #2269 from xypron/libtool-bin
devel/libtool-bin: new package
Christian Schoenebeck [Sun, 24 Jan 2016 19:04:26 +0000 (20:04 +0100)]
ddns-scripts: Ver.2.6.0 - support hostip and uclient-fetch
- add support for "hostip" to get_registered_ip() as alternative to "Bind host" package https://dev.openwrt.org/ticket/20893#comment:5
- allow to send updates using compiled-in certificate file/path of curl/wget #2242 #2243 #2245
- add support for uclient-fetch / libustream-ssl.so
- remove /128 prefix-filter in get_local_ip() via interface #2268
- add dyndns.org to services_ipv6 https://forum.openwrt.org/viewtopic.php?id=62103
- readd duckdns.org to services #2251 (lost somewhere in data heaven)
- add zzzz.io service #2302
- updated tld_names.dat
Signed-off-by: Christian Schoenebeck <christian.schoenebeck@gmail.com>
Miroslav Lichvar [Sun, 24 Jan 2016 17:16:09 +0000 (18:16 +0100)]
chrony: update to 2.2.1
Fixes CVE-2016-1567.
Signed-off-by: Miroslav Lichvar <mlichvar0@gmail.com>
Felix Fietkau [Sun, 24 Jan 2016 09:17:21 +0000 (10:17 +0100)]
tgt: depend on @KERNEL_AIO and @KERNEL_DIRECT_IO instead of modifying the global kernel config
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Heinrich Schuchardt [Sat, 16 Jan 2016 09:14:15 +0000 (10:14 +0100)]
devel/libtool-bin: new package
GNU libtool is used to ease the usage of shared libraries in Makefiles.
The new package libtool-bin contains the script libtoolize which is used
to prepare a package to use libtool.
Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Florian Fainelli [Wed, 20 Jan 2016 21:16:28 +0000 (13:16 -0800)]
net: Import cifs-utils
Import cifs-utils from old packages:
* update to 6.4
* add upstream patch to fix builds with musl
* add license information
* add myself as maintainer
Signed-off-by: Florian Fainelli <florian@openwrt.org>
Noah Meyerhans [Sat, 23 Jan 2016 17:28:58 +0000 (09:28 -0800)]
bind: Allow packages to be built with optional filter-aaaa option
Signed-off-by: Noah Meyerhans <frodo@morgul.net>
Noah Meyerhans [Sat, 23 Jan 2016 15:57:37 +0000 (07:57 -0800)]
bind: upgrade to 9.9.8-P3
Fixes:
* CVE-2015-8704
* CVE-2015-3193
* CVE-2015-8000
* CVE-2015-8461
Signed-off-by: Noah Meyerhans <frodo@morgul.net>
Naoir [Sat, 23 Jan 2016 14:52:09 +0000 (15:52 +0100)]
Merge pull request #2267 from jow-/CVE-2015-8607
perl: ensure File::Spec::canonpath() preserves taint [CVE-2015-8607]
Marcel Denia [Sat, 23 Jan 2016 13:17:39 +0000 (14:17 +0100)]
perl-test-harness: Update to 3.36
Signed-off-by: Marcel Denia <naoir@gmx.net>
Marcel Denia [Sat, 23 Jan 2016 13:17:13 +0000 (14:17 +0100)]
perl-html-parser: Update to 3.72
Signed-off-by: Marcel Denia <naoir@gmx.net>
Marcel Denia [Sat, 23 Jan 2016 13:15:55 +0000 (14:15 +0100)]
perl-uri: Update to 1.71
Signed-off-by: Marcel Denia <naoir@gmx.net>
Felix Fietkau [Wed, 20 Jan 2016 23:38:58 +0000 (00:38 +0100)]
gdbm: add a gettext dependency
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Felix Fietkau [Wed, 20 Jan 2016 23:36:04 +0000 (00:36 +0100)]
boost: do not select @BUILD_NLS, it affects the whole tree
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Felix Fietkau [Wed, 20 Jan 2016 19:30:04 +0000 (20:30 +0100)]
treewide: use $(STAGING_DIR)/host instead of $(STAGING_DIR_HOST), sync with changes in trunk
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Felix Fietkau [Wed, 20 Jan 2016 19:12:37 +0000 (20:12 +0100)]
glib2: sync with default host prefix change
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Felix Fietkau [Wed, 20 Jan 2016 15:14:55 +0000 (16:14 +0100)]
glib2: the host build also needs --with-libiconv=gnu
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Ted Hess [Wed, 20 Jan 2016 14:50:28 +0000 (09:50 -0500)]
Merge pull request #2279 from antonlacon/minidlna-1.1.x
minidlna: update to 1.1.5
Felix Fietkau [Wed, 20 Jan 2016 13:55:38 +0000 (14:55 +0100)]
glib2: use --with-libiconv=gnu, always required as of trunk r48396
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Steven Barth [Wed, 20 Jan 2016 13:45:46 +0000 (14:45 +0100)]
strongswan: bump to 5.3.5
Signed-off-by: Steven Barth <steven@midlink.org>
Steven Barth [Wed, 20 Jan 2016 13:28:17 +0000 (14:28 +0100)]
Merge pull request #2289 from stintel/strongswan
strongswan: preserve /etc/ipsec.d during upgrade
Steven Barth [Wed, 20 Jan 2016 13:18:05 +0000 (14:18 +0100)]
Merge pull request #2263 from jsiverskog/mdnsresponder_bump_version
mdnsresponder: bump to 576.30.4.
Felix Fietkau [Wed, 20 Jan 2016 12:23:47 +0000 (13:23 +0100)]
libffi: fix MIPS softfloat build issue with current binutils
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Nikos Mavrogiannopoulos [Wed, 20 Jan 2016 08:18:41 +0000 (09:18 +0100)]
Merge pull request #2277 from notnyt/feature_cryptodev
cryptodev-linux: bump to 1.8
Stijn Tintel [Tue, 19 Jan 2016 14:36:15 +0000 (15:36 +0100)]
strongswan: preserve /etc/ipsec.d during upgrade
Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be>
Karl Palsson [Mon, 18 Jan 2016 17:40:52 +0000 (17:40 +0000)]
mosquitto: properly separate the passwd utility
Building both variants improperly tried to include the passwd utility
for the non-ssl variant, as the variable was set for the ssl variant.
Use properly separated install tasks to install additional files, rather
than hacking around inside the single target.
Signed-off-by: Karl Palsson <karlp@remake.is>
Karl Palsson [Tue, 19 Jan 2016 10:40:18 +0000 (10:40 +0000)]
mosquitto: fix old whitespace bug
Introduced back in 2014
Fixes: cd21cbb82eacf5c2dc60a8dd8dfa51f978b98193
Signed-off-by: Karl Palsson <karlp@tweak.net.au>
Daniel Golle [Mon, 18 Jan 2016 00:22:52 +0000 (01:22 +0100)]
tracertools: update source, fixes bug on little-endian systems
and improves collectd support
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Alexandru Ardelean [Mon, 18 Jan 2016 12:55:37 +0000 (14:55 +0200)]
python3-setuptools: upgrade to version 19.4
Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
Alexandru Ardelean [Mon, 18 Jan 2016 12:54:28 +0000 (14:54 +0200)]
python-setuptools: upgrade to version 19.4
Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
Jo-Philipp Wich [Mon, 18 Jan 2016 08:50:37 +0000 (09:50 +0100)]
mosquitto: fix whitespace error introduced with
7a6a575887db81934369f38616d137005ed9ea96
Signed-off-by: Jo-Philipp Wich <jow@openwrt.org>
Álvaro Fernández Rojas [Sun, 17 Jan 2016 21:39:22 +0000 (22:39 +0100)]
Merge pull request #2276 from notnyt/master
flashrom: include io.h to fix compile error
notnyt [Sun, 17 Jan 2016 21:19:29 +0000 (16:19 -0500)]
cryptodev-linux: bump to 1.8
This fixes compile time errors using kernel 4.3 and above
Signed-off-by: Rob Mosher <nyt-openwrt@countercultured.net>
notnyt [Sun, 17 Jan 2016 20:58:09 +0000 (15:58 -0500)]
flashrom: include io.h to fix compile error
This patch includes sys/io.h from flash.h to fix compile errors
Signed-off-by: Rob Mosher <nyt-openwrt@countercultured.net>
Heinrich Schuchardt [Sun, 17 Jan 2016 18:39:37 +0000 (19:39 +0100)]
net/apache: use @APACHE download facility
Instead of explicitly specyfing an Apache mirror use the
@APACHE download facility.
Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Heinrich Schuchardt [Sun, 17 Jan 2016 18:24:32 +0000 (19:24 +0100)]
libs/apr-util: use @APACHE download facility
Instead of explicitly specyfing an Apache mirror use the
@APACHE download facility.
Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Heinrich Schuchardt [Sun, 17 Jan 2016 18:21:04 +0000 (19:21 +0100)]
libs/apr: use @APACHE download facility
Instead of explicitly specyfing an Apache mirror use the
@APACHE download facility.
Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Peter Wagner [Fri, 15 Jan 2016 20:23:18 +0000 (21:23 +0100)]
openssh: update to 7.1p2
Signed-off-by: Peter Wagner <tripolar@gmx.at>
Karl Palsson [Fri, 15 Jan 2016 09:30:57 +0000 (09:30 +0000)]
mosquitto: Bump to version 1.4.7
Minor changes mostly unrelated to OpenWRT.
Full changelog at http://mosquitto.org/2015/12/version-1-4-7-released/
Signed-off-by: Karl Palsson <karlp@remake.is>
Karl Palsson [Fri, 15 Jan 2016 09:29:41 +0000 (09:29 +0000)]
mosquitto: optionally include mosquitto_passwd utility
Many users of the SSL build of mosquitto need the passwd utility for
managing keys.
Fixes github issue #1909
Signed-off-by: Karl Palsson <karlp@remake.is>
Peter Wagner [Thu, 14 Jan 2016 16:50:10 +0000 (17:50 +0100)]
ntpd: update to 4.2.8p5
Signed-off-by: Peter Wagner <tripolar@gmx.at>
Jo-Philipp Wich [Thu, 14 Jan 2016 11:17:56 +0000 (12:17 +0100)]
perl: ensure File::Spec::canonpath() preserves taint [CVE-2015-8607]
Beginning in PathTools 3.47 and/or perl 5.20.0, the File::Spec::canonpath()
routine returned untained strings even if passed tainted input. This defect
undermines the guarantee of taint propagation, which is sometimes used to
ensure that unvalidated user input does not reach sensitive code.
This defect was found and reported by David Golden of MongoDB, and a patch
was provided by Tony Cook.
References:
* https://rt.perl.org/Public/Bug/Display.html?id=126862
* https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8607
Signed-off-by: Jo-Philipp Wich <jow@openwrt.org>
Daniel Golle [Thu, 14 Jan 2016 00:38:06 +0000 (01:38 +0100)]
lvm2: update to 2.02.139
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Daniel Golle [Thu, 14 Jan 2016 00:22:05 +0000 (01:22 +0100)]
ccid: update to 1.4.22
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Daniel Golle [Thu, 14 Jan 2016 00:16:02 +0000 (01:16 +0100)]
pcsc-lite: update to 1.8.15
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Daniel Golle [Thu, 14 Jan 2016 00:11:17 +0000 (01:11 +0100)]
libinput: include cmdline tools in package
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Daniel Golle [Thu, 14 Jan 2016 00:05:48 +0000 (01:05 +0100)]
libinput: update to 1.1.4
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Daniel Golle [Thu, 14 Jan 2016 00:21:44 +0000 (01:21 +0100)]
libevdev: update to 1.4.6
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Daniel Golle [Wed, 13 Jan 2016 23:07:53 +0000 (00:07 +0100)]
squid: build-depend on libext2fs
squid uses libcom_err, a static library provided by libext2fs
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Jacob Siverskog [Wed, 13 Jan 2016 17:15:04 +0000 (18:15 +0100)]
mdnsresponder: bump to 576.30.4.
Signed-off-by: Jacob Siverskog <jacob@teenage.engineering>
Jo-Philipp Wich [Mon, 11 Jan 2016 09:48:55 +0000 (10:48 +0100)]
Merge pull request #2260 from cshore/pull-request-collectd-prevent-perl-bindings
utils/collectd: Really prevent perl bindings