Romain Naour
dbf660aea8
toolchain-external: bump version of Linaro ARM toolchain to 2017.08
...
GDB has been updated to 8.0 version in the release.
https://releases.linaro.org/components/toolchain/binaries/6.4-2017.08
Tested with qemu_arm_vexpress_defconfig.
6.4-2017.08 includes several patches for glibc 2.23 mitigating
some of the "stack clash" vulnerabilities reported by Qualys.
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
https://git.linaro.org/toolchain/glibc.git/log/?h=linaro/2.23/master
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit aed5a0fcf7 )
Signed-off-by: Marc Gonzalez <marc_gonzalez@sigmadesigns.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-16 09:18:03 +02:00
Romain Naour
7f7c6ea114
toolchain-external: bump Linaro AArch64 toolchain to 2017.02
...
Tested with qemu-2.7.1-2.fc25 and the qemu_aarch64_virt_defconfig
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 641fe0e392 )
Signed-off-by: Marc Gonzalez <marc_gonzalez@sigmadesigns.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-16 09:17:37 +02:00
Romain Naour
a3b9426194
toolchain-external: bump Linaro ARMeb toolchain to 2017.02
...
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 52f059f38d )
Signed-off-by: Marc Gonzalez <marc_gonzalez@sigmadesigns.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-16 09:17:12 +02:00
Romain Naour
6d3669070a
toolchain-external: bump Linaro ARM toolchain to 2017.02
...
Tested with qemu-2.7.1-2.fc25 and the qemu_arm_vexpress_defconfig
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 075d26900b )
Signed-off-by: Marc Gonzalez <marc_gonzalez@sigmadesigns.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-16 09:16:53 +02:00
Luca Ceresoli
33156ba957
bzip2: fix passing of TARGET_MAKE_ENV to make
...
TARGET_MAKE_ENV is not passed to make because it is on a different
line without a backslash.
Signed-off-by: Luca Ceresoli <luca@lucaceresoli.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 7690bc0335 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 23:08:35 +02:00
Fabio Estevam
334401cc8d
linux-headers: bump 3.2.x and 4.{4, 9, 13}.x series
...
[Peter: drop 4.13.x bump]
Signed-off-by: Fabio Estevam <festevam@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 2cd4c84586 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 23:07:27 +02:00
Peter Korsgaard
fd49d225a3
libnss: security bump to version 3.33
...
Fixes CVE-2017-7805 - Martin Thomson discovered that nss, the Mozilla
Network Security Service library, is prone to a use-after-free vulnerability
in the TLS 1.2 implementation when handshake hashes are generated. A remote
attacker can take advantage of this flaw to cause an application using the
nss library to crash, resulting in a denial of service, or potentially to
execute arbitrary code.
Also add a hash for the license file while we're at it.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 746502418f )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 23:03:45 +02:00
Baruch Siach
ff4d2c18b6
libnss: bump to version 3.31
...
Fixes build with gcc 7.
https://hg.mozilla.org/projects/nss/rev/0dca14409fef
Fixes:
http://autobuild.buildroot.net/results/b71/b71e4e003ec5753708a07cfd04e3025c93f80e67/
http://autobuild.buildroot.net/results/66d/66d31923824d34df3b20a363a1346df1c00ae222/
Signed-off-by: Baruch Siach <baruch@tkos.co.il >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b39e6dbed1 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 23:03:33 +02:00
Peter Korsgaard
4720122d2c
libnspr: bump version to 4.17
...
libnss 3.33 needs libnspr >= 4.17.
Also add a hash for the license file while we're at it.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit b136309324 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 23:02:14 +02:00
Baruch Siach
59af8829ae
libnspr: bump to version 4.15
...
Signed-off-by: Baruch Siach <baruch@tkos.co.il >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit f234748a48 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 23:01:59 +02:00
Bernd Kuhls
5ec89c79ee
package/x11r7/xserver_xorg-server: security bump version to 1.19.5
...
Fixes
xfixes: unvalidated lengths (CVE-2017-12183)
Xi: fix wrong extra length check in ProcXIChangeHierarchy
(CVE-2017-12178)
dbe: Unvalidated variable-length request in ProcDbeGetVisualInfo
(CVE-2017-12177)
Unvalidated extra length in ProcEstablishConnection (CVE-2017-12176)
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit e7713abf89 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 22:54:12 +02:00
Cam Hutchison
e42b881a59
docs/manual: fix BR2_EXTERNAL path typo
...
Signed-off-by: Cam Hutchison <camh@xdna.net >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 0c76d89e54 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 22:47:35 +02:00
Alexander Mukhin
4d63e4332d
hostapd: fix upstream URL
...
hostapd project URL has been changed to w1.fi/hostapd.
The old domain epitest.fi has expired.
Signed-off-by: Alexander Mukhin <alexander.i.mukhin@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 8a2396b90a )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 22:11:52 +02:00
Thomas De Schampheleire
79da53917e
support/kconfig: fix usage typo and align verb tenses
...
Fix typo 'selectes' -> 'selects'.
Additionally, change 'will exclude' to 'excludes' to align with 'selects'.
Signed-off-by: Thomas De Schampheleire <thomas.de_schampheleire@nokia.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 787f4fee71 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-15 22:07:47 +02:00
Peter Korsgaard
cd12cca54c
xlib_libXfont{, 2}: add upstream security fixes
...
Fixes the following security issues:
CVE-2017-13720 - Check for end of string in PatternMatch
CVE-2017-13722 - pcfGetProperties: Check string boundaries
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 46a54b6464 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 22:26:42 +02:00
Bernd Kuhls
dad64de907
package/iucode-tool: security bump to version 2.2
...
Version 2.1.1 fixed CVE-2017-0357:
657ce44ac4
Dropped IUCODE_TOOL_CONF_ENV after version 2.2 added a configure check
for libargp:
b14bed6771
Added hash for license file.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 1462c07914 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 22:22:24 +02:00
Romain Naour
a8c1ce2172
package/x11r7/xserver_xorg-server: rename patch directory after the last version bump
...
The last bump [1] forgot to rename the patch directory and remove
upstream patches.
We still need to fix the monotonic clock check which doesn't work
when cross-compiling.
[1] 436659c55f
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Cc: Bernd Kuhls <bernd.kuhls@t-online.de >
Cc: Peter Korsgaard <peter@korsgaard.com >
Acked-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 7cf8a08feb )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 17:07:00 +02:00
Bernd Kuhls
2b5fe1c29e
package/x11r7/xserver_xorg-server: security bump to version 1.19.4
...
Fixes CVE-2017-13721 & CVE-2017-13723:
https://lists.x.org/archives/xorg-announce/2017-October/002809.html
Added all hashes provided by upstream.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 436659c55f )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 14:35:33 +02:00
Bernd Kuhls
0ccdc2c089
package/x11r7/xserver_xorg-server: glamor support needs egl
...
Glamor support in xserver_xorg-server depends on gbm:
https://cgit.freedesktop.org/xorg/xserver/tree/configure.ac#n2100
Gbm is provided by mesa3d only if egl is enabled:
https://git.buildroot.net/buildroot/tree/package/mesa3d/mesa3d.mk#n167
This patch adds libegl as additional prerequisite for enabling glamor
support in xserver_xorg-server.
Fixes
http://autobuild.buildroot.net/results/04d/04d93745d63fcfbea070c0126862b49f1b6f473e/
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit 5b4bcbdafb )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 14:35:13 +02:00
Romain Naour
521b95c13a
package/x11r7/xserver_xorg-server: bump to version 1.19.3
...
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Cc: Bernd Kuhls <bernd.kuhls@t-online.de >
[Thomas: fix hash file, as noticed by Bernd.]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit f0772c92c8 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 14:31:38 +02:00
Bernd Kuhls
a67eba5404
package/x11r7/xserver_xorg-server: bump version to 1.19.2
...
Changed _SITE according to URL mentioned in upstream release note.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit d48cc32653 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 14:31:32 +02:00
Peter Korsgaard
42f38b057c
libcurl: security bump to version 7.56.0
...
Drop upstreamed patch.
Fixes CVE-2017-1000254 - FTP PWD response parser out of bounds read:
https://curl.haxx.se/docs/adv_20171004.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 9d95b93e5d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 14:27:26 +02:00
Baruch Siach
b2609e56d6
libcurl: fix build without threads
...
When c-ares is not enabled libcurl enables the threaded DNS resolver by
default. Make sure the threaded resolvers is disabled when the toolchain
does not support threads.
Add upstream patch that fixes the configure option for disabling the
threaded resolver.
Fixes:
http://autobuild.buildroot.net/results/39f/39fa63fb2ecb75e4b2521d1ee3dfa357c4e5c594/
http://autobuild.buildroot.net/results/dfd/dfd296086d0d6bed73b92fe2fa4ba5434dddf796/
Signed-off-by: Baruch Siach <baruch@tkos.co.il >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 10e998e7cc )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 14:27:15 +02:00
Baruch Siach
6588353417
libcurl: bump to version 7.55.1
...
Drop upstream patch.
Add license hash.
Signed-off-by: Baruch Siach <baruch@tkos.co.il >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 3f6c10df67 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 14:26:59 +02:00
Peter Korsgaard
b7fb34cc88
qemu: change to .tar.xz format
...
And use the official download location.
Suggested-by: Baruch Siach <baruch@tkos.co.il >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b79547014d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 10:04:20 +02:00
Peter Korsgaard
37fa007ab6
qemu: security bump to version 2.8.1.1
...
Fixes the following security issues and adds a number of other bigfixes:
2.8.1: Changelog:
https://lists.gnu.org/archive/html/qemu-devel/2017-03/msg06332.html
CVE-2017-2615 - display: cirrus: oob access while doing bitblt copy backward
mode
CVE-2017-2620 - display: cirrus: out-of-bounds access issue while in
cirrus_bitblt_cputovideo
CVE-2017-2630 - nbd: oob stack write in client routine drop_sync
2.8.1.1 Changelog:
https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg03460.html
CVE-2017-7471 - 9p: virtfs allows guest to change filesystem attributes on
host
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit af0f2d2bbc )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 10:03:26 +02:00
Thomas Petazzoni
12ff4e2348
qemu: fix user mode emulation build on ARM
...
This commit adds a patch that adjusts how the mcontext structure is used
on ARM with a uClibc C library.
Fixes:
http://autobuild.buildroot.net/results/79900b22c190e883b6d9a3075e1286ec95840ae1/
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 40c5fff466 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 10:02:54 +02:00
Andrey Yurovsky
6dee0734aa
package: qemu: bump version to 2.8.0
...
This adds a CPU definition for the Cortex A7 along with improvements described
here: http://wiki.qemu-project.org/ChangeLog/2.8
Tested on an ARM Cortex A7 target (both target and host builds). The change log
does not describe any incompatible changes that would affect buildroot targets
as far as I am aware.
Signed-off-by: Andrey Yurovsky <yurovsky@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit f56b13897b )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 10:02:03 +02:00
Bernd Kuhls
b1cb4d9ea9
linux-headers: bump 4.{4, 9, 13}.x series
...
[Peter: drop 4.13.x bump]
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit 55a6159dcd )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 08:51:37 +02:00
Evgeniy Didin
5648030f9a
qt: Allow enabling of QtWebKit with GCC 6+
...
Building Qt with QtWebKit on configuration step there is
a check which disables QtWebKit build with GCC 6+.
Back in the day nobody thought about building Qt with GCC
version greater than 5.x. And now with modern GCCs like
6.x and 7.x this assumption gets in the way.
Given in Buildroot today we don't have GCC older than 4.9
it should be safe to remove now meaningless check completely
by adding patch to qt.
Signed-off-by: Evgeniy Didin <didin@synopsys.com >
Cc: Alexey Brodkin <abrodkin@synopsys.com >
Cc: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit f95bb8562e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-14 08:49:42 +02:00
Baruch Siach
ad0eab0037
dnsmasq: security bump to version 2.78
...
Supported Lua version is now 5.2.
Add licenses hash.
Fixes a number of security issues:
CVE-2017-13704 - Crash when DNS query exceeded 512 bytes (a regression
in 2.77, so technically not fixed by this bump)
CVE-2017-14491 - Heap overflow in DNS code
CVE-2017-14492 - Heap overflow in IPv6 router advertisement code
CVE-2017-14493 - Stack overflow in DHCPv6 code
CVE-2017-14494 - Information leak in DHCPv6
CVE-2017-14496 - Invalid boundary checks allows a malicious DNS queries
to trigger DoS
CVE-2017-14495 - Out-of-memory Dos vulnerability
Signed-off-by: Baruch Siach <baruch@tkos.co.il >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit e77fdc90e3 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-10-03 10:08:59 +02:00
Peter Korsgaard
0c0b7006bd
linux-headers: bump 3.18.x version to 3.18.72
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-29 10:03:27 +02:00
Peter Korsgaard
de4be78ba1
git: security bump to version 2.12.5
...
Release notes:
https://public-inbox.org/git/xmqqy3p29ekj.fsf@gitster.mtv.corp.google.com/
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-29 09:54:16 +02:00
Bernd Kuhls
48fb7bbdca
package/openvpn: security bump to version 2.4.4
...
Fixes CVE-2017-12166:
https://community.openvpn.net/openvpn/wiki/CVE-2017-12166
Changelog:
https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit aa070c802e )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-29 09:50:10 +02:00
Bernd Kuhls
dbc02af63b
linux-headers: bump 4.{4, 9, 13}.x series
...
[Peter: drop 4.13.x bump]
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit dd4dd79635 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-29 09:49:11 +02:00
Fabio Estevam
183c367ddc
wandboard: genimage: Pass an offset for the rootfs
...
Pass an offset of 1MB for the start of the rootfs.
Otherwise we get rootfs corruption when the bootloader is manually
written to the SD card.
Signed-off-by: Fabio Estevam <fabio.estevam@nxp.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit 82c1445fc4 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-29 09:44:41 +02:00
Peter Korsgaard
8ee6c1d60e
Update for 2017.02.6
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017.02.6
2017-09-24 22:17:59 +02:00
Baruch Siach
07ddb40567
libidn: fix build without makeinfo
...
Build fails when the makeinfo utility is not installed on the host.
Fixes:
http://autobuild.buildroot.net/results/dfd/dfdfb34ed81ba3a4b7a7271be482e75eca849dbf/
http://autobuild.buildroot.net/results/b33/b33c0b0e6b1033ab1d1294a91b869ee6adcd391a/
http://autobuild.buildroot.net/results/940/9401cc10f6da6a2e3453ebc65ce573c370733fb5/
Signed-off-by: Baruch Siach <baruch@tkos.co.il >
Tested-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit f6227928cd )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-24 21:36:27 +02:00
Baruch Siach
46b07c8a87
libidn: add fix for CVE-2017-14062
...
Add upstream patch fixing CVE-2017-14062:
Integer overflow in the decode_digit function in puny_decode.c in
Libidn2 before 2.0.4 allows remote attackers to cause a denial of
service or possibly have unspecified other impact.
This issue also affects libidn.
Unfortunately, the patch also triggers reconf of the documentation
subdirectory, since lib/punycode.c is listed in GDOC_SRC that is defined
in doc/Makefile.am. Add autoreconf to handle that.
Signed-off-by: Baruch Siach <baruch@tkos.co.il >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 49cb795f79 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-24 21:36:09 +02:00
Peter Seiderer
bde9621d0f
gst1-plugins-bad: fix build against openjpeg 2.2
...
Add upstream patch to fix build against openjpeg 2.2.
Fixes [1]:
gstopenjpeg.h:42:37: fatal error: openjpeg-2.1/openjpeg.h: No such file or directory
[1] http://autobuild.buildroot.net/results/90f1f7838f08e3a557be27470406d4d84dbcc828
[Peter: drop meson changes for 2017.02.x]
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 3a5d4db954 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-24 16:46:53 +02:00
Peter Korsgaard
5f9d99944a
openjpeg: fix build without C++ support
...
Fixes:
http://autobuild.buildroot.net/results/e2f/e2ff0a7fa2b911157edf6c43a8eed797b22edd46/
http://autobuild.buildroot.net/results/670/6706339e7df2f2e7d0d7a15663bed185ca55c2a1/
Openjpeg is written in C, but with the move to CMake the build system now
errors out if a C++ compiler isn't available. Fix it by patching the
CMakeLists.txt to not require C++ support.
Patch submitted upstream:
https://github.com/uclouvain/openjpeg/pull/1027
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be >
(cherry picked from commit d2911fec6a )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-24 09:01:14 +02:00
Olivier Schonken
1a22a5fcb3
openjpeg: Fix malloc poison issue
...
The malloc poison issue has been fixed upstream, this patch will thus only
be temporary.
Fixes the following autobuild issues
sparc | http://autobuild.buildroot.net/results/c1b7a316ca2a4db49023f304dbc7fd5fed05bd9d
bfin | http://autobuild.buildroot.net/results/031ece7a72e76a9155938cb283de859bd12a8171
sh4 | http://autobuild.buildroot.net/results/88664451f71c12ccd94e874d408fbb680bea1695
xtensa | http://autobuild.buildroot.net/results/fbede64a5a86d4868b6da0ab1275e75803235af0
powerpc | http://autobuild.buildroot.net/results/6c641650509048039b18fbeb010dbca0f0fc5292
microblazeel | http://autobuild.buildroot.net/results/fa2d5272b2db73cbfa441ead9250157c5626ab15
mips64el | http://autobuild.buildroot.net/results/fc96f6628f71e05d9a74e0e13e50178d29a2c495
sh4 | http://autobuild.buildroot.net/results/a6d6a6dcb9b4fa250edaaf5935762c5820457b23
x86_64 | http://autobuild.buildroot.net/results/47b4ca2cc661582d86830b9353a6c8af86e4ba35
arc | http://autobuild.buildroot.net/results/08e2e4eca6c3dbde8116a649dbf46e52ded45d10
arc | http://autobuild.buildroot.net/results/899fa044aab7ee28acfa71544f2105da4a5c97d5
arm | http://autobuild.buildroot.net/results/6016f6885b21d6e8c6199a6833c7acce6210ecc6
arm | http://autobuild.buildroot.net/results/adbb3c76497e89161535c711de98809a0fa168a7
or1k | http://autobuild.buildroot.net/results/de3ef69a72d2c2082e202fbed702c53a51274fef
mips64el | http://autobuild.buildroot.net/results/39b186b13001a810e0992b52321f1015b445d2fd
x86_64 | http://autobuild.buildroot.net/results/22c6a29a1ded6aedf01adfdfcf26302248dba80c
arm | http://autobuild.buildroot.net/results/b62c54b727eb5f576c4a517a69c495b537c3b69a
m68k | http://autobuild.buildroot.net/results/a826561c5786be5f0088b50b633210593e23ffff
arm | http://autobuild.buildroot.net/results/d32ec927a5e4d5644cb3641014bcf6ebe5c14490
Signed-off-by: Olivier Schonken <olivier.schonken@gmail.com >
Tested-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 19d8081865 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-24 09:01:06 +02:00
Peter Korsgaard
4adb61ec73
tor: security bump to version 0.2.9.12
...
Fixes CVE-2017-0380: Stack disclosure in hidden services logs when
SafeLogging disabled
For more details, see:
https://trac.torproject.org/projects/tor/ticket/23490
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-23 23:10:24 +02:00
Peter Korsgaard
8fbd4de7c2
CHANGES: update with recent changes
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-23 11:04:39 +02:00
Peter Korsgaard
1f8ed52c55
bind: use http:// instead of ftp:// for site
...
To avoid issues with firewalls blocking ftp.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 771bb2d58d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-23 10:29:35 +02:00
Peter Korsgaard
b449b86637
bind: bump to version 9.11.2
...
Adds support for the new ICANN DNSSEC root key for the upcoming KSK rollover
(Oct 11):
https://www.icann.org/resources/pages/ksk-rollover
For more details, see the release notes:
https://kb.isc.org/article/AA-01522
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit f3e3b36159 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-23 10:29:25 +02:00
Peter Korsgaard
b6b99d28ef
gdk-pixbuf: security bump to version 2.36.10
...
Fixes the following security issues:
CVE-2017-2862 - An exploitable heap overflow vulnerability exists in the
gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A
specially crafted jpeg file can cause a heap overflow resulting in remote
code execution. An attacker can send a file or url to trigger this
vulnerability.
CVE-2017-2870 - An exploitable integer overflow vulnerability exists in the
tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with
Clang. A specially crafted tiff file can cause a heap-overflow resulting in
remote code execution. An attacker can send a file or a URL to trigger this
vulnerability.
CVE-2017-6311 - gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows
context-dependent attackers to cause a denial of service (NULL pointer
dereference and application crash) via vectors related to printing an error
message.
The host version now needs the same workaround as we do for the target to
not pull in shared-mime-info.
Also add a hash for the license file while we're at it.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 3853675ae0 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-22 09:00:35 +02:00
Vicente Olivert Riera
4ec2c80824
gdk-pixbuf: bump version to 2.36.6
...
Signed-off-by: Vicente Olivert Riera <Vincent.Riera@imgtec.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 0fcf03eb5d )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-22 09:00:17 +02:00
Gustavo Zacarias
6c99140688
gdk-pixbuf: copy loaders.cache later on
...
Trying to copy loaders.cache from host-gdk-pixbuf to the gdk-pixbuf
build directory in the post-patch hook is too early when using TLP (it
breaks horribly) since host-gdk-pixbuf isn't built yet during the
massive unpack/patch cycle.
Switch it to the pre-build hook instead which ensures that gdk-pixbuf
dependencies were already built.
Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 1f4e1656bc )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-22 09:00:08 +02:00
Gustavo Zacarias
0995804d44
gdk-pixbuf: bump to version 2.36.5
...
This release needs a new tweak regarding loaders.cache - it's now used
to build the thumbnailer.
Since we already generate it using the host variant for the target we
can re-use this for the build step.
It's not necessary to used the tweaked version since the build one is
only used to account for mime types, not the plugins/loaders themselves.
Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com >
(cherry picked from commit 487b419cc6 )
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2017-09-22 08:59:57 +02:00