Adrian Perez de Castro
c8c96d9c35
package/xdg-dbus-proxy: fix tarball name in hash file
...
Fixes: 487761a5b2 ("package/xdg-dbus-proxy: bump to version 0.1.5")
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit d4fc46f751 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-26 18:58:31 +02:00
Adrian Perez de Castro
b77df1db5b
package/xdg-dbus-proxy: bump to version 0.1.5
...
Version 0.1.5 mainly fixes handling of paths with more than 255
characters. Release notes:
https://github.com/flatpak/xdg-dbus-proxy/releases/tag/0.1.5
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 487761a5b2 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-26 18:40:10 +02:00
Bernd Kuhls
89a71e4222
{linux, linux-headers}: bump 6.1.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 2e1890db65 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-26 18:36:20 +02:00
Joachim Wiberg
3b5e9e24c4
package/inadyn: bump to v2.12.0
...
New features and DDNS provider support (IPv64.net), but also a lot of
fixes to regressions introduced in v2.11.0, e.g.:
- dynv6.com not working at all, regression in v2.11.0
- Regression in DDNS provider names, introduced in v2.11.0:
- dyndns@3322.org
- dyndns@he.net
- default@dynv6.com
- ipv6tb@he.net
From https://github.com/troglobit/inadyn/releases/tag/v2.12.0
Signed-off-by: Joachim Wiberg <troglobit@gmail.com >
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit dc84952eb3 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-26 18:33:01 +02:00
Fabrice Fontaine
78ea668c6f
package/casync: fix build with gcc >= 13
...
Fix the following build failure with gcc >= 13:
In file included from ../src/compressor.c:3:
../src/compressor.h:59:59: error: unknown type name 'size_t'
59 | int compressor_input(CompressorContext *c, const void *p, size_t sz);
| ^~~~~~
../src/compressor.h:19:1: note: 'size_t' is defined in header '<stddef.h>'; did you forget to '#include <stddef.h>'?
18 | #include "cacompression.h"
+++ |+#include <stddef.h>
19 |
Fixes:
- http://autobuild.buildroot.org/results/ab08f3b90d253db45643dd058b80ae1dd5f49d0f
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit 39e092a06e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-26 13:13:33 +02:00
Fabrice Fontaine
7616363468
package/ksmbd-tools: security bump to version 3.4.9
...
Fix two security issues that reported by ZDI.
https://github.com/cifsd-team/ksmbd-tools/releases/tag/3.4.7
https://github.com/cifsd-team/ksmbd-tools/releases/tag/3.4.8
https://github.com/cifsd-team/ksmbd-tools/releases/tag/3.4.9
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit 5eac719129 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-26 13:11:48 +02:00
Woodrow Douglass
9d863d5315
package/opencv4-contrib: properly note dependencies between modules
...
Also, add myself to the DEVELOPERS file
Signed-off-by: Woodrow Douglass <wdouglass@carnegierobotics.com >
[Arnout: fix typo BR2_PACKAGE_OPENCV4_LIB_OBJDETECCT]
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit a7736afaca )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-26 13:04:22 +02:00
Brandon Maier
377941f670
Makefile: fix SDK relocation for per-package-dirs
...
The relocate-sdk.sh script does not work correctly when
BR2_PER_PACKAGE_DIRECTORIES is enabled. relocate-sdk.sh expects
everything to point at $HOST_DIR, but each package will be pointing at
its $(O)/per-package/*/host.
Use the same command for scrubing host paths during the build, to scrub
to the final host directory location.
Signed-off-by: Brandon Maier <Brandon.Maier@collins.com >
Acked-by: Charles Hardin <ckhardin@gmail.com >
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit 25e60fbe1c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-25 23:10:24 +02:00
Titouan Christophe
d4393ae271
package/redis: security bump to v7.0.14
...
This contains security fixes for:
- CVE-2022-24834
- CVE-2023-36824
- CVE-2023-41053
- CVE-2023-45145
See the release notes:
https://raw.githubusercontent.com/redis/redis/7.0.14/00-RELEASENOTES
Signed-off-by: Titouan Christophe <titouanchristophe@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-24 17:16:01 +02:00
Peter Korsgaard
fe50c054bc
Update for 2023.08.2
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023.08.2
2023-10-15 23:07:16 +02:00
Fabrice Fontaine
bbe4466ad7
package/libhtp: bump to version 0.5.45
...
Needed by suricata 6.0.14:
http://autobuild.buildroot.net/results/b9d/b9df165b014698e5b4c2d218574947476cf23216/
https://github.com/OISF/libhtp/blob/0.5.45/ChangeLog
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit d821de0e46 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 22:46:02 +02:00
Bernd Kuhls
7b860e69ae
package/exim: security bump version to 4.96.2
...
Release notes: https://seclists.org/oss-sec/2023/q4/107
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit 5759ec066a )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:32:32 +02:00
Fabrice Fontaine
175bc20117
package/usbguard: fix build with gcc >= 13
...
Fix the following build failure with gcc >= 13:
In file included from src/Library/Base64.cpp:23:
src/Library/Base64.hpp:34:34: error: 'uint8_t' does not name a type
34 | std::string base64Encode(const uint8_t* buffer, size_t buflen);
| ^~~~~~~
Fixes:
- http://autobuild.buildroot.org/results/1a08823020c37a73f4e4a40f47b02fca3f159748
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 05db019ea6 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:26:13 +02:00
Fabrice Fontaine
9c442c86e5
package/mutt: fix libgpgme static build
...
Fix the following static build failure with libgpgme raised since at
least bump to version 2.2.9 in commit
7a2afdb7b1 :
/home/autobuild/autobuild/instance-11/output-1/host/lib/gcc/sh4a-buildroot-linux-musl/11.3.0/../../../../sh4a-buildroot-linux-musl/bin/ld: /home/autobuild/autobuild/instance-11/output-1/host/sh4a-buildroot-linux-musl/sysroot/usr/lib/libgpgme.a(assuan-support.o): in function `my_usleep':
assuan-support.c:(.text+0x260): undefined reference to `__assuan_usleep'
Fixes:
- http://autobuild.buildroot.org/results/0680dbc95601fcd8cdf07b926ea5e9be2079c7bf
- http://autobuild.buildroot.org/results/b4f2d1ad77fb8b97accc4150d8249de145cb9cf4
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b518b0f161 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:25:28 +02:00
Gaël PORTAY
6f8b4a006a
board/raspberrypi: fix typo in comment
...
This fixes a typo by dropping off the spurious x in ensure.
Signed-off-by: Gaël PORTAY <gael.portay@rtone.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 3381a08433 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:24:35 +02:00
Adam Duskett
3f854cea47
package/rauc: bump version to 1.10.1
...
Bugfix release:
https://github.com/rauc/rauc/releases/tag/v1.10.1
Signed-off-by: Adam Duskett <adam.duskett@amarulasolutions.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit e55770e882 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:24:29 +02:00
Adam Duskett
461155fc78
package/systemd: bump version to 254.5
...
All tests passed in Debian 11 with the following command:
./support/testing/run-tests tests.init.test_systemd
Signed-off-by: Adam Duskett <adam.duskett@amarulasolutions.com >
Acked-by: Norbert Lange <nolange79@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 1c6b1ee63f )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:24:02 +02:00
Fabrice Fontaine
72b50b9043
package/netsnmp: fix musl build
...
Fix the following musl build failure raised since bump to version 5.9.4
in commit 868603755c :
large_fd_set.c: In function 'LFD_SET':
../include/net-snmp/net-snmp-config.h:1614:30: error: unknown type name 'unknown'; did you mean 'union'?
1614 | #define NETSNMP_FD_MASK_TYPE unknown
| ^~~~~~~
Fixes:
- http://autobuild.buildroot.org/results/394ebf93621c33dc2ddf370297268e6de9de7c9a
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit dad81003c9 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:23:15 +02:00
Fabrice Fontaine
8f5cf8d488
package/pound: force libopenssl
...
Force libopenssl to avoid the following build failure with libressl
raised since bump to version 4.8 in commit
525cb6a8fb :
pound.c: In function 'main':
pound.c:971:27: error: 'l_id' undeclared (first use in this function)
971 | CRYPTO_set_id_callback (l_id);
| ^~~~
Fixes:
- http://autobuild.buildroot.org/results/692db714aa8b0dcfb67fd99977fb6f33c5d4810c
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 648502bdbd )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:22:50 +02:00
Fabrice Fontaine
a9a7d01b5c
package/nmap: fix build with libressl >= 3.5.0
...
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 796ebbcf34 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:20:38 +02:00
Yann E. MORIN
d354a46ad3
package/gcc: remove leftover from legacy PowerPC patch
...
In commit 0c82f3f635 (package/gcc: remove powerpc conditional patching
logic), the macro defining the conditional patch was removed, but it was
still referenced and expanded in the apply-patches hook.
Drop that now.
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
Cc: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 84cdd92f01 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:20:11 +02:00
Bernd Kuhls
a4cfbf072e
package/samba4: security bump version to 4.18.8
...
Release notes: https://www.samba.org/samba/history/samba-4.18.8.html
Fixes CVE-2023-3961, CVE-2023-4091, CVE-2023-4154, CVE-2023-42669 &
CVE-2023-42670.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 2dc61bfa76 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-15 20:19:30 +02:00
Peter Korsgaard
d4ad6cefee
package/libcue: security bump to version 2.3.0
...
Fixes the following security issue:
CVE-2023-43641: Out-of-bounds array access in track_set_index
https://github.com/lipnitsk/libcue/security/advisories/GHSA-5982-x7hv-r9cj
For more details, see the github writeup:
https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 3aee3a326d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:44:22 +02:00
Peter Korsgaard
bc0f65857e
package/go: security bump to version 1.20.10
...
Fixes CVE-2023-39325: rapid stream resets can cause excessive work
A malicious HTTP/2 client which rapidly creates requests and immediately
resets them can cause excessive server resource consumption. While the
total number of requests is bounded to the http2.Server.MaxConcurrentStreams
setting, resetting an in-progress request allows the attacker to create a
new request while the existing one is still executing.
go1.20.10 (released 2023-10-10) includes a security fix to the net/http
package.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:42:32 +02:00
Bernd Kuhls
ac51d2a903
{linux, linux-headers}: bump 4.{14, 19}.x / 5.{4, 10, 15}.x / 6.{1, 5}.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit d71743b736 )
[Peter: drop 6.5.x bump]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:27:52 +02:00
Bernd Kuhls
58bf67263b
package/wireless-regdb: bump version to 2023.09.01
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 29b6e170b7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:25:43 +02:00
Bernd Kuhls
5fb0d39752
package/python3: bump version to 3.11.6
...
Release notes: https://www.python.org/downloads/release/python-3116/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 337485b232 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:24:52 +02:00
Bernd Kuhls
0f95c3b4c2
{linux, linux-headers}: bump 5.15.x / 6.{1, 5}.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 003cdd5de3 )
[Peter: drop 6.5.x bump]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:21:58 +02:00
Peter Korsgaard
d982e4b6da
package/gstreamer1-editing-services: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 8c8ff42674 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:19:14 +02:00
Peter Korsgaard
206402e5a9
package/gst-omx: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6339e7f413 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:18:53 +02:00
Peter Korsgaard
73075f6684
package/gst1-rtsp-vaapi: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 688dcef3d7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:18:46 +02:00
Peter Korsgaard
3e167b8c65
package/gst1-rtsp-server: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 7a0cbea0e3 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:18:22 +02:00
Peter Korsgaard
7c83c55df6
package/gst1-python: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 3aff0c2cde )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:18:15 +02:00
Peter Korsgaard
102ef88df4
package/gst1-libav: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 57fc4d90d0 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:17:55 +02:00
Peter Korsgaard
5922259b41
package/gst1-devtools: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 637cf8fdab )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:17:45 +02:00
Peter Korsgaard
8c48d23e5d
package/gst1-plugins-ugly: security bump to version 1.22.6
...
Fixes the following security issues:
ZDI-CAN-21443: Heap-based buffer overflow in the RealMedia file demuxer when
handling malformed files in GStreamer versions before 1.22.5 / 1.20.7.
https://gstreamer.freedesktop.org/security/sa-2023-0004.html
ZDI-CAN-21444: Heap-based buffer overflow in the RealMedia file demuxer when
handling malformed files in GStreamer versions before 1.22.5 / 1.20.7.
https://gstreamer.freedesktop.org/security/sa-2023-0005.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 7f2571f594 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:17:25 +02:00
Peter Korsgaard
47c4d44e5c
package/gst1-plugins-bad: security bump to version 1.22.6
...
Fixes the following security issues:
CVE-2023-37329: Heap-based buffer overflow in the PGS blu-ray subtitle
decoder when handling certain files in GStreamer versions before 1.22.4 /
1.20.7.
https://gstreamer.freedesktop.org/security/sa-2023-0003.html
CVE-2023-40474: Heap-based buffer overflow in the MXF file demuxer when
handling malformed files with uncompressed video in GStreamer versions
before 1.22.6.
https://gstreamer.freedesktop.org/security/sa-2023-0006.html
CVE-2023-40475: Heap-based buffer overflow in the MXF file demuxer when
handling malformed files with AES3 audio in GStreamer versions before
1.22.6.
https://gstreamer.freedesktop.org/security/sa-2023-0007.html
CVE-2023-40476: Stack-based buffer overflow in the H.265 video parser when
handling malformed H.265 video streams in GStreamer versions before 1.22.6.
https://gstreamer.freedesktop.org/security/sa-2023-0008.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 19fe76b8b4 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:17:11 +02:00
Peter Korsgaard
63a69b18f4
package/gst1-plugins-good: security bump to version 1.22.6
...
Fixes CVE-2023-37327: Heap-based buffer overflow in the FLAC parser when
handling malformed image tags in GStreamer versions before 1.22.4 / 1.20.7.
https://gstreamer.freedesktop.org/security/sa-2023-0001.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 40c3696131 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:16:55 +02:00
Peter Korsgaard
6f006bbedc
package/gst1-plugins-base: security bump to version 1.22.6
...
Fixes CVE-2023-37328: Heap-based buffer overflow in the subparse subtitle
parser when handling certain SRT subtitle files in GStreamer versions before
1.22.4 / 1.20.7.
https://gstreamer.freedesktop.org/security/sa-2023-0002.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 14e2374592 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:16:45 +02:00
Peter Korsgaard
b73a345f4f
package/gstreamer1: bump to version 1.22.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 133ced8e02 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:16:06 +02:00
Peter Korsgaard
85e9e4a2fc
package/cups: add upstream security fix for CVE-2023-4504
...
Fixes CVE-2023-4504: Postscript Parsing Heap Overflow
https://github.com/OpenPrinting/cups/security/advisories/GHSA-pf5r-86w9-678h
https://takeonme.org/cves/CVE-2023-4504.html
There is a 2.4.7 release with this fix, but upstream unfortunately broke
!gnutls builds, so backport the security fix instead:
https://github.com/OpenPrinting/cups/issues/762
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b9d9497019 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:13:54 +02:00
Jan Čermák
f9d1275643
package/libcurl: security bump to 8.4.0
...
Fixes following two vulnerabilities:
* CVE-2023-38545: SOCKS5 heap buffer overflow
https://curl.se/docs/CVE-2023-38545.html
* CVE-2023-38546: cookie injection with none file
https://curl.se/docs/CVE-2023-38546.html
Signed-off-by: Jan Čermák <sairon@sairon.cz >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 30dd60ba7e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:13:02 +02:00
Francois Perrad
93800e3256
package/mbedtls: security bump to version 2.28.5
...
Fixes the following security issue:
CVE-2023-43615: Buffer overread in TLS stream cipher suites
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2023-10-1/
Signed-off-by: Francois Perrad <francois.perrad@gadz.org >
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit 26762e3009 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:09:29 +02:00
Francois Perrad
a2cbf289d4
package/mbedtls: bump to version 2.28.4
...
Signed-off-by: Francois Perrad <francois.perrad@gadz.org >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
(cherry picked from commit 7dc2462a8e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 20:09:01 +02:00
Thomas Petazzoni
010cd4640f
DEVELOPERS: add Thomas Petazzoni for nodejs
...
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Arnout Vandecappelle <arnout@mind.be >
(cherry picked from commit 65dfac5d11 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 17:44:29 +02:00
Bernd Kuhls
620fb8fb0f
package/exim: security bump version to 4.96.1
...
Fixes CVE-2023-42114, CVE-2023-42115, CVE-2023-42116:
https://exim.org/static/doc/security/CVE-2023-zdi.txt
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 657d10b34b )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 17:42:36 +02:00
Daniel Lang
1f2a2b8338
package/efl: bump to version 1.26.3
...
This is a bug-fix release.
See: https://www.enlightenment.org/news/2022-09-16-efl-1.26.3
Signed-off-by: Daniel Lang <dalang@gmx.at >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6037f9387a )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 17:18:33 +02:00
Daniel Lang
ddf9ad1065
package/netsnmp: security bump to version 5.9.4
...
CVE-2022-44792 handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c
in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can
be used by a remote attacker (who has write access) to cause the
instance to crash via a crafted UDP packet, resulting in Denial of
Service.
CVE-2022-44793 handle_ipv6IpForwarding in
agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a
NULL Pointer Exception bug that can be used by a remote attacker to
cause the instance to crash via a crafted UDP packet, resulting in
Denial of Service.
The pgp key was changed [0] as the old one expired [1].
[0]: 90a6d98aae /
[1]: https://github.com/net-snmp/net-snmp/issues/595
Signed-off-by: Daniel Lang <dalang@gmx.at >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 868603755c )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 17:17:18 +02:00
Giulio Benetti
e31a049bbc
package/wilc-driver: fix build failure with Linux 6.3+
...
Add local patches pending upstream to fix build failure on Linux 6.3+
Fixes:
http://autobuild.buildroot.net/results/3b954399aa3ffab9609da1fc381f38f28bd8eb9f
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit c495aab883 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 17:16:11 +02:00
Fabrice Fontaine
9401df1989
package/sslh: add SSLH_CPE_ID_VENDOR
...
cpe:2.3:a:sslh_project:sslh is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/detail/3E1DF528-5507-4919-A3EC-4283949BE06F
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 5fcd2ef29d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-10-13 17:15:24 +02:00