Fabrice Fontaine
d3e83e9aca
package/python-autobahn: add CPE variables
...
cpe:2.3:a:crossbar:autobahn is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Acrossbar%3Aautobahn
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 28b19ccb48 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:28:33 +02:00
Fabrice Fontaine
73fb529563
package/python-tqdm: add CPE variables
...
cpe:2.3:a:tqdm_project:tqdm is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Atqdm_project%3Atqdm
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit ca6fab6ef9 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:27:52 +02:00
Fabrice Fontaine
1c2113c95a
package/python-requests: add CPE variables
...
cpe:2.3:a:python:requests is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Apython%3Arequests
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 6c5cf37880 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:27:46 +02:00
Fabrice Fontaine
cd647bfb8d
package/python-engineio: add PYTHON_ENGINEIO_CPE_ID_VENDOR
...
cpe:2.3:a:python-engineio_project:python-engineio is a valid CPE
identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Apython-engineio_project%3Apython-engineio
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 901689bfcc )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:27:19 +02:00
Fabrice Fontaine
56b1f4b885
package/python-keyring: add CPE variables
...
cpe:2.3:a:python:keyring is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Apython%3Akeyring
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 14614d63f7 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:27:12 +02:00
Fabrice Fontaine
a6f4494217
package/gstreamer1/gstreamer1: add CPE variables
...
cpe:2.3:a:gstreamer_project:gstreamer is a valid CPE identifier for this
package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Agstreamer_project%3Agstreamer
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 38fb1ad2a0 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:26:19 +02:00
Fabrice Fontaine
5fc94b549e
package/gstreamer1/gst1-rtsp-server: add CPE variables
...
cpe:2.3:a:gstreamer_project:gst-rtsp-server is a valid CPE identifier
for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Agstreamer_project%3Agst-rtsp-server
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 75d795c493 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:25:54 +02:00
Fabrice Fontaine
15116e42cb
package/gstreamer1/gst1-plugins-bad: add CPE variables
...
cpe:2.3:a:freedesktop:gst-plugins-bad is a valid CPE identifier for
this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Afreedesktop%3Agst-plugins-bad
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 13c2242034 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:25:47 +02:00
Fabrice Fontaine
cdd3886dc0
package/udisks: add UDISKS_CPE_ID_VENDOR
...
cpe:2.3:a:freedesktop:udisks is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Afreedesktop%3Audisks
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 6381183d49 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:24:22 +02:00
Fabrice Fontaine
4446b0353b
package/x11r7/libxcb: add LIBXCB_CPE_ID_VENDOR
...
cpe:2.3:a:x:libxcb is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxcb
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 4a321afa83 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:24:08 +02:00
Fabrice Fontaine
53d7efef54
package/x11r7/xlib_libdmx: add CPE variables
...
cpe:2.3:a:x:libdmx is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibdmx
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit a2f0a2147a )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:23:25 +02:00
Fabrice Fontaine
75293e8d6e
package/x11r7/xlib_libXxf86vm: add CPE variables
...
cpe:2.3:a:x:libxxf86vm is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxxf86vm
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 1ec75d777e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:23:19 +02:00
Fabrice Fontaine
87283a0b0d
package/x11r7/xlib_libXxf86dga: add CPE variables
...
cpe:2.3:a:x:libxxf86dga is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxxf86dga
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 8017840f04 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:23:14 +02:00
Fabrice Fontaine
cefbc30569
package/x11r7/libXres: add CPE variables
...
cpe:2.3:a:x:libxres is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxres
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit ec86e30e66 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:22:47 +02:00
Fabrice Fontaine
88cfd19e23
package/x11r7/xlib_libXpm: add CPE variables
...
cpe:2.3:a:libxpm_project:libxpm is a valid CPE identifier for this
package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Alibxpm_project%3Alibxpm
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit da67bf6418 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:22:42 +02:00
Fabrice Fontaine
51a053d2ed
package/x11r7/xlib_libFS: add CPE variables
...
cpe:2.3:a:x:libfs is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibfs
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 9784dcb385 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:21:08 +02:00
Fabrice Fontaine
49e83f6e10
package/x11r7/xlib_libICE: add CPE variables
...
cpe:2.3:a:freedesktop:libice is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Afreedesktop%3Alibice
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 3b4980677b )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:21:02 +02:00
Fabrice Fontaine
5e19718287
package/x11r7/xlib_libXt: add CPE variables
...
cpe:2.3:a:x:libxt is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxt
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit e0d0fec9a8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:19:54 +02:00
Fabrice Fontaine
b9bd35609a
package/x11r7/xlib_libXtst: add CPE variables
...
cpe:2.3:a:x:libxtst is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxtst
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 74e049a0f3 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:19:44 +02:00
Fabrice Fontaine
33c5f42ea4
package/x11r7/xlib_libXcursor: add CPE variables
...
cpe:2.3:a:x:libxcursor is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxcursor
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit d3a25a98d4 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:19:28 +02:00
Fabrice Fontaine
3fbde2c92e
package/x11r7/xlib_libXdmcp: add CPE variables
...
cpe:2.3:a:x.org:libxdmcp is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax.org%3Alibxdmcp
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 3558493454 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:19:21 +02:00
Fabrice Fontaine
d52d49b188
package/x11r7/xlib_libXext: add CPE variables
...
cpe:2.3:a:x:libxext is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxext
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit b1336915b6 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:18:56 +02:00
Fabrice Fontaine
89d08aeba3
package/x11r7/xlib_libXfixes: add CPE variables
...
cpe:2.3:a:x:libxfixes is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxfixes
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 73ddf01dd8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:18:49 +02:00
Fabrice Fontaine
3b4c01ddd7
package/x11r7/xlib_libXinerama: add CPE variables
...
cpe:2.3:a:x:libxinerama is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxinerama
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 713a76560b )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:18:08 +02:00
Fabrice Fontaine
db7de62da9
package/x11r7/xlib_libXfont2: add CPE variables
...
cpe:2.3:a:x:libxfont is a valid CPE identifier for this package:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Ax%3Alibxfont
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 68436b2335 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:18:03 +02:00
Peter Seiderer
b74235234b
package/localedef: fix host gcc-11.x compile
...
Add two upstream patches fixing host gcc-11.x compile.
Fixes:
- https://bugs.busybox.net/show_bug.cgi?id=13806
In file included from ../include/pthread.h:1,
from ../sysdeps/nptl/thread_db.h:25,
from ../nptl/descr.h:32,
from ../sysdeps/x86_64/nptl/tls.h:130,
from ../sysdeps/generic/libc-tsd.h:44,
from ./localeinfo.h:224,
from programs/ld-ctype.c:37:
../sysdeps/nptl/pthread.h:734:47: error: argument 1 of type ‘struct __jmp_buf_tag *’ declared as a pointer [-Werror=array-parameter=]
734 | extern int __sigsetjmp (struct __jmp_buf_tag *__env, int __savemask) __THROWNL;
| ~~~~~~~~~~~~~~~~~~~~~~^~~~~
In file included from ../include/setjmp.h:2,
from ../nptl/descr.h:24,
from ../sysdeps/x86_64/nptl/tls.h:130,
from ../sysdeps/generic/libc-tsd.h:44,
from ./localeinfo.h:224,
from programs/ld-ctype.c:37:
../setjmp/setjmp.h:54:46: note: previously declared as an array ‘struct __jmp_buf_tag[1]’
54 | extern int __sigsetjmp (struct __jmp_buf_tag __env[1], int __savemask) __THROWNL;
| ~~~~~~~~~~~~~~~~~~~~~^~~~~~~~
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
(cherry picked from commit 4174f79a57 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 23:16:45 +02:00
Fabrice Fontaine
2b1836d9ec
package/libxslt: fix build with latest libxml2
...
Build is broken since bump of libxml2 to version 2.9.11 in commit
a241dcec41 because libxslt calls the
following command "${XML_CONFIG} --libs print" which will return an
error code since
2a357ab99e
Fixes:
- http://autobuild.buildroot.org/results/47ceb8c24c9ead8a450b7fea3266f760d6b77b4f
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Reviewed-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 7320e5dd62 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:25:47 +02:00
Peter Korsgaard
aaeaac8595
package/prosody: security bump to version 0.11.9
...
Fixes the following security issues:
- CVE-2021-32918: DoS via insufficient memory consumption controls
It was discovered that default settings leave Prosody susceptible to
remote unauthenticated denial-of-service (DoS) attacks via memory
exhaustion when running under Lua 5.2 or Lua 5.3. Lua 5.2 is the default
and recommended Lua version for Prosody 0.11.x series.
- CVE-2021-32920: DoS via repeated TLS renegotiation causing excessive CPU
consumption
It was discovered that Prosody does not disable SSL/TLS renegotiation,
even though this is not used in XMPP. A malicious client may flood a
connection with renegotiation requests to consume excessive CPU resources
on the server.
- CVE-2021-32921: Use of timing-dependent string comparison with sensitive
values
It was discovered that Prosody does not use a constant-time algorithm for
comparing certain secret strings when running under Lua 5.2 or later.
This can potentially be used in a timing attack to reveal the contents of
secret strings to an attacker.
- CVE-2021-32917: Use of mod_proxy65 is unrestricted in default
configuration
mod_proxy65 is a file transfer proxy provided with Prosody to facilitate
the transfer of files and other data between XMPP clients.
It was discovered that the proxy65 component of Prosody allows open access
by default, even if neither of the users have an XMPP account on the local
server, allowing unrestricted use of the server’s bandwidth.
- CVE-2021-32919: Undocumented dialback-without-dialback option insecure
The undocumented option ‘dialback_without_dialback’ enabled an
experimental feature for server-to-server authentication. A flaw in this
feature meant it did not correctly authenticate remote servers, allowing a
remote server to impersonate another server when this option is enabled.
For more details, see the advisory:
https://prosody.im/security/advisory_20210512/
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 9c108afab8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:25:13 +02:00
Peter Korsgaard
e4ee7144ac
test_docker_compose.py: Test the volume mount feature
...
Extend docker_compose_test() to expose /bin on the host to the container
through a volume mount and verify that /bin/busybox can be downloaded and
contains the right data.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit aa31d10808 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:24:11 +02:00
Peter Korsgaard
3adc69a086
test_docker_compose.py: Test the port publish feature
...
Extend docker_test() to expose a random (8888) port to verify that doesn't
fail, and extend the docker-compose test to run the busybox httpd in the
background, expose that as port 80 and verify that /etc/resolv.conf could be
fetched by wget.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 4915b692c8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:23:59 +02:00
Peter Korsgaard
1a48c70e07
package/docker-engine: fix port forwarding for hosts without IPv6
...
docker-engine 20.10.6 broke container port forwarding for hosts without IPv6
support:
docker: Error response from daemon: driver failed programming external
connectivity on endpoint naughty_moore
(038e9ed4b5ea77e1c52462d6d04ad001fbad9beb185a6511aadc217c8a271608): Error
starting userland proxy: listen tcp6 [::]:80: socket: address family not
supported by protocol.
Add a libnetwork patch from an upstream pull request to fix this, after
adjusting the patch to apply to docker-engine (which has libnetwork vendored
under vendor/github.com/docker/libnetwork):
- https://github.com/moby/libnetwork/pull/2635 ,
- https://github.com/moby/moby/pull/42322
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 2fd33900f5 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:23:47 +02:00
Fabrice Fontaine
8ff560df67
package/live555: security bump to version 2021.05.03
...
Fix CVE-2021-28899: Vulnerability in the
AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession,
and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession
subclasses in Networks LIVE555 Streaming Media before 2021.3.16.
http://live555.com/liveMedia/public/changelog.txt
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6ad1c7f12e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:23:26 +02:00
Fabrice Fontaine
8108c70cc6
package/libxml2: bump to version 2.9.12
...
Brown-paper bag release:
b48e77cf4f
Update indentation in hash file (two spaces)
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b304a458bd )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:22:52 +02:00
Dick Olsson
ddd01c9ea5
DEVELOPERS: add package/bitcoin for Dick Olsson
...
Signed-off-by: Dick Olsson <hi@senzilla.io >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b6c1151936 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:22:11 +02:00
Bernd Kuhls
32cd16d5d6
DEVELOPERS: add myself for bitcoin
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 0845329e27 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:22:03 +02:00
Yann E. MORIN
12d3b998b2
package/opentyrian: switch to using github
...
OpenTyrian was previously managed in a Mercurial repository hosted on
Bitbucket. Mid-2020, Bitbucket shut off all its Mercurial repositories:
https://bitbucket.org/blog/sunsetting-mercurial-support-in-bitbucket
Since then, OpenTyrian's source code is inacessible, but we have had no
build failure associated as there is an old archive hosted on s.b.o, so
that all builds fallback to downloading that:
http://sources.buildroot.net/opentyrian/opentyrian-9c9f0ec3532b.tar.gz
However, the project has been revived (kinda) on github:
https://github.com/opentyrian/opentyrian
Git commit cf5dbeb69eebd9ef9afc4473088d9469b79589eb has been found to
be the closest, both in content and date, to the Mercuail reference
9c9f0ec3532b we were using. The only deltas are in Mercurial-specific
files:
b/.hg_archival.txt | 5 0 5 0 -----
b/.hgtags | 2 1 1 0 +-
2 files changed, 1 insertion(+), 6 deletions(-)
While at it, add a hash file.
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
Cc: Julien Boibessot <julien.boibessot@armadeus.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 64e7c63528 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:21:14 +02:00
Peter Seiderer
0b3a2db21c
package/libgeos: fix comment dependencies (binutils-bug-12464, binutils-bug-27597)
...
The comment dependencies need to be the inverse of the package
dependencies (fixes comment shown in menuconfig even if the package
is available).
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 03a8d70f52 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-17 21:20:24 +02:00
Adrian Perez de Castro
cdbc10dddf
package/libxml2: security bump to version 2.9.11
...
Update libxml2 to version 2.9.11, which incorporates all the patches
carried by Buildroot (which are hence removed), and includes fixes for
CVE-2020-7595, CVE-2019-20388, CVE-2020-24977, and CVE-2021-3541 (at
least), as per
https://gitlab.gnome.org/GNOME/libxml2/-/issues/186#note_1104945
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit a241dcec41 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-14 19:23:16 +02:00
Bernd Kuhls
fdedf7c984
package/postgresql: security bump version to 13.3
...
Fixes CVE-2021-32027, CVE-2021-32028 & CVE-2021-32029:
https://www.postgresql.org/about/news/postgresql-133-127-1112-1017-and-9622-released-2210/
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b544587806 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-14 19:23:11 +02:00
Peter Korsgaard
cbc530bfa6
package/rt-tests: add patch to fix compatibility with make 3.81
...
Fixes:
http://autobuild.buildroot.net/results/cf7c4f360f5464c700788cc8299fd086544c80e8/build-end.log
Older GNU make versions don't like the explicit undefine. It isn't really
needed as ifdef handles undefined and defined-to-the-empty-string the same
way, so just drop the undefine logic.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b8a1301e81 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-14 19:22:03 +02:00
Fabrice Fontaine
35627e9222
package/bitcoin: security bump to version 0.21.1
...
Tag as a security bump as having an up to date bitcoin is important:
https://patchwork.ozlabs.org/project/buildroot/patch/20200202085526.35742-1-james.hilliard1@gmail.com
https://github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-0.21.1.md
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit a7a58df5f0 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-14 19:21:46 +02:00
Bernd Kuhls
ef91c329b2
package/vlc: security bump version to 3.0.14
...
Removed patch 0002 which was applied upstream:
41caaa08cd
Renumbered remaining patches.
Release notes:
https://www.videolan.org/vlc/releases/3.0.13.html
https://www.videolan.org/vlc/releases/3.0.12-update.html
Version 3.0.13 fixes VideoLAN-SB-VLC-3013:
https://www.videolan.org/security/sb-vlc3013.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6a07591484 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-14 19:21:19 +02:00
Peter Korsgaard
76b4f9e9b6
Update for 2021.02.2
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021.02.2
2021-05-12 11:06:28 +02:00
Joachim Wiberg
ce583c4d2d
package/sysklogd: bump to version 2.2.3
...
https://github.com/troglobit/sysklogd/releases/tag/v2.2.3
Signed-off-by: Joachim Wiberg <troglobit@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 8036c23d59 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-12 11:01:21 +02:00
Bernd Kuhls
a2a1768d2a
package/php: bump version to 7.4.19
...
Changelog: https://www.php.net/ChangeLog-7.php#7.4.19
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit f4d0191689 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-12 08:05:29 +02:00
Bernd Kuhls
89688a2d24
package/tor: bump version to 0.4.5.8
...
Release notes: https://blog.torproject.org/node/2031
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 294e939a51 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-12 08:05:20 +02:00
Marcin Niestroj
0fe2e0ab07
package/lvm2: use http instead of ftp
...
ftp links do not seem to be accessible anymore. Replace them with http.
Signed-off-by: Marcin Niestroj <m.niestroj@grinn-global.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 92378c6063 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-11 22:14:37 +02:00
Sébastien Szymanski
d277ca3305
package/boost: fix broken BOOST_SITE URL
...
Current URL returns 403 error:
--2021-05-10 10:04:12-- https://dl.bintray.com/boostorg/release/1.75.0/source/boost_1_75_0.tar.bz2
Resolving dl.bintray.com... 18.193.131.58, 3.66.199.110
Connecting to dl.bintray.com|18.193.131.58|:443... connected.
HTTP request sent, awaiting response... 403 Forbidden
2021-05-10 10:04:12 ERROR 403: Forbidden.
Bintray has been sunset on May 1st:
https://jfrog.com/blog/into-the-sunset-bintray-jcenter-gocenter-and-chartcenter/
Update the URL to the new upstream location to fix this issue.
Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 345bb23050 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-11 22:13:28 +02:00
Fabrice Fontaine
a8112b55f9
package/rust: security bump to version 1.52.0
...
Fix CVE-2020-36317, CVE-2020-36318, CVE-2020-36323, CVE-2021-28877,
CVE-2021-28875, CVE-2021-28876, CVE-2021-28878 and CVE-2021-28879
https://github.com/rust-lang/rust/blob/1.52.0/RELEASES.md
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 0a4a69bb48 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-11 22:12:47 +02:00
Peter Korsgaard
442ec6253f
CHANGES: update with recent changes
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-05-10 20:37:12 +02:00