Johan Oudinet
f8e3ffad3d
package/erlang-p1-stringprep: bump to version 1.0.17
...
Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-06 20:46:41 +01:00
Johan Oudinet
4b944ef18a
package/erlang-p1-sip: bump to version 1.0.30
...
Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-06 20:46:23 +01:00
Johan Oudinet
3381a7fdcb
package/erlang-p1-oauth2: bump to version 0.6.5
...
Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-06 20:45:54 +01:00
Johan Oudinet
03322dd77e
package/erlang-p1-cache-tab: bump to version 1.0.20
...
Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-06 20:45:15 +01:00
Johan Oudinet
a0f8a35319
package/erlang-eimp: bump to version 1.0.12
...
While at it, add the hash file which was missing.
Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-06 20:44:58 +01:00
Johan Oudinet
01c6c72f7e
package/erlang-lager: bump to version 3.6.10
...
Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-06 20:44:46 +01:00
Johan Oudinet
16c5dd68c5
package/erlang-p1-utils: bump to version 1.0.16
...
Signed-off-by: Johan Oudinet <johan.oudinet@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-06 20:44:45 +01:00
Christopher McCrory
61d7face88
configs/raspberrypi0w_defconfig: fix post script args
...
Commit ada40afb32 updated the raspberrypi*defconfigs to use
-add-miniuart-bt-overlay instead of -add-pi3-miniuart-bt-overlay.
Update raspberrypi0w_defconfig also.
Signed-off-by: Christopher McCrory <chrismcc@gmail.com >
Reviewed-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2020-01-06 18:56:40 +01:00
Fabrice Fontaine
d78acc2288
package/pcsc-lite: bump to version 1.8.26
...
Remove patch (already in version) and so drop autoreconf
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-06 16:43:04 +01:00
Fabrice Fontaine
7ccf0795b8
package/ncmpc: bump to version 0.36
...
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-06 16:42:43 +01:00
Fabrice Fontaine
8380bec8aa
package/bubblewrap: bump to version 0.4.0
...
musl is supported since
300da62ab6
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-06 16:42:09 +01:00
Bartosz Golaszewski
c9b7c85623
package/libsigrokdecode: bump to v0.5.3
...
Remove the patch that's now upstream.
Signed-off-by: Bartosz Golaszewski <bgolaszewski@baylibre.com >
[Peter: drop _AUTORECONF]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-06 13:15:25 +01:00
Bartosz Golaszewski
c0304066e5
package/libsigrok: bump to v0.5.2
...
Remove the patch that's now upstream.
Signed-off-by: Bartosz Golaszewski <bgolaszewski@baylibre.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-06 13:02:11 +01:00
Bartosz Golaszewski
e82d927da6
package/doxygen: bump to v1.8.17
...
Signed-off-by: Bartosz Golaszewski <bgolaszewski@baylibre.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-06 13:02:02 +01:00
Bernd Kuhls
41ca1dc1ac
{linux, linux-headers}: bump 4.19.x / 5.4.x series
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-06 08:24:01 +01:00
Christian Stewart
39cffd5356
package/docker-cli: security bump to 19.03.5
...
Fixes the following security vulnerabilities:
- CVE-2019-14271: In Docker 19.03.x before 19.03.1 linked against the GNU C
Library (aka glibc), code injection can occur when the nsswitch facility
dynamically loads a library inside a chroot that contains the contents of
the container
Signed-off-by: Christian Stewart <christian@paral.in >
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:54:38 +01:00
Christian Stewart
0161899ae5
package/docker-engine: security bump to 19.03.5
...
Fixes the following security vulnerabilities:
- CVE-2019-14271: In Docker 19.03.x before 19.03.1 linked against the GNU C
Library (aka glibc), code injection can occur when the nsswitch facility
dynamically loads a library inside a chroot that contains the contents of
the container
Signed-off-by: Christian Stewart <christian@paral.in >
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:39:13 +01:00
Christian Stewart
f40f2bae81
package/docker-containerd: security bump to 1.2.11
...
Fixes the following security vulnerabilities:
containerd 1.2.9/gRPC:
- CVE-2019-9512: Some HTTP/2 implementations are vulnerable to ping floods,
potentially leading to a denial of service. The attacker sends continual
pings to an HTTP/2 peer, causing the peer to build an internal queue of
responses. Depending on how efficiently this data is queued, this can
consume excess CPU, memory, or both
- CVE-2019-9514: Some HTTP/2 implementations are vulnerable to a reset
flood, potentially leading to a denial of service. The attacker opens a
number of streams and sends an invalid request over each stream that
should solicit a stream of RST_STREAM frames from the peer. Depending on
how the peer queues the RST_STREAM frames, this can consume excess memory,
CPU, or both
- CVE-2019-9515: Some HTTP/2 implementations are vulnerable to a settings
flood, potentially leading to a denial of service. The attacker sends a
stream of SETTINGS frames to the peer. Since the RFC requires that the
peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS
frame is almost equivalent in behavior to a ping. Depending on how
efficiently this data is queued, this can consume excess CPU, memory, or
both
containerd 1.2.10/runc:
- CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through
19.03.2-ce and other products, allows AppArmor restriction bypass because
libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a
malicious Docker image can mount over a /proc director
Signed-off-by: Christian Stewart <christian@paral.in >
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:38:19 +01:00
Christian Stewart
dbbf08849b
package/runc: security bump to 1.0.0-rc9
...
Fixes the following security vulnerability:
- CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through
19.03.2-ce and other products, allows AppArmor restriction bypass because
libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a
malicious Docker image can mount over a /proc directory.
Signed-off-by: Christian Stewart <christian@paral.in >
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:22:19 +01:00
Bernd Kuhls
004be1eb9c
package/nano: bump version to 4.7
...
Release notes:
4.6: https://lists.gnu.org/archive/html/info-gnu/2019-11/msg00011.html
4.7: https://lists.gnu.org/archive/html/info-gnu/2019-12/msg00005.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:01:58 +01:00
Bernd Kuhls
9146d92abf
package/libmicrohttpd: bump version to 0.9.69
...
Release notes:
https://lists.gnu.org/archive/html/info-gnu/2019-12/msg00003.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:01:33 +01:00
Bernd Kuhls
ff9dc529a1
package/jsoncpp: bump version to 1.9.2
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:01:15 +01:00
Bernd Kuhls
38621c2fdf
package/tvheadend: bump version
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 22:00:24 +01:00
Bernd Kuhls
3b9e772f1f
package/libva-utils: bump version to 2.6.0
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:59:51 +01:00
Bernd Kuhls
55de2558ba
package/libva-intel-driver: bump version to 2.4.0
...
Removed patch applied upstream.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:58:57 +01:00
Bernd Kuhls
0cedf59742
package/libva: bump version to 2.6.0
...
Added bugfix patch to fix known issue suggested by upstream:
https://github.com/intel/libva/releases/tag/2.6.0
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:57:51 +01:00
Bernd Kuhls
c907b15549
package/x11r7/xdriver_xf86-video-intel: bump version
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:55:56 +01:00
Bernd Kuhls
69b7940d51
package/{mesa3d, mesa3d-headers}: bump version to 19.3.1
...
Removed patch 0004, applied upstream.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:55:16 +01:00
Bernd Kuhls
68af58dac2
{linux, linux-headers}: bump 4.{4, 9, 14, 19}.x / 5.4.x series
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:54:42 +01:00
Bernd Kuhls
6343127e7a
package/linux-headers: drop support for 5.3.x headers
...
The 5.3.x series is now EOL so remove the option and add legacy
handling for it.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:54:33 +01:00
Bernd Kuhls
d40377e4da
package/tor: bump version to 0.4.2.5
...
Release notes:
https://blog.torproject.org/new-release-0425-also-0417-0406-and-0359
Updated license hash due to upstream commit:
https://gitweb.torproject.org/tor.git/commit/LICENSE?h=maint-0.4.2&id=272265efbd89c4c2589316a20cf27064def21911
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:54:08 +01:00
Bernd Kuhls
62d72f9ec2
package/sqlite: bump version to 3.30.1
...
Release notes: https://sqlite.org/releaselog/3_30_1.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:52:37 +01:00
Bernd Kuhls
ace7bb7724
package/x11r7/xdriver_xf86-video-sis: bump version to 0.12.0
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:36:34 +01:00
Bernd Kuhls
f9a88bdc75
package/x11r7/xlib_libXpm: bump version to 3.5.13
...
Removed patch applied upstream:
https://cgit.freedesktop.org/xorg/lib/libXpm/commit/?id=7af7c5e275b69daedee3696bee1e880586f30373
Removed autoreconf.
Added all hashes provided by upstream.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:35:54 +01:00
Bernd Kuhls
f79d59d58b
package/x265: bump version to 3.2.1
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:32:39 +01:00
Bernd Kuhls
306aa32fd8
package/stellarium: bump version to 0.19.3
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:31:13 +01:00
Bernd Kuhls
4b60aff888
package/libvpx: bump version to 1.8.2
...
Changelog:
https://github.com/webmproject/libvpx/blob/master/CHANGELOG
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:31:04 +01:00
Bernd Kuhls
6c1e4d98f3
package/cpio: security bump to version 2.13
...
Removed patch fixing CVE-2016-2037 which was applied upstream.
This release fixes CVE-2015-1197, CVE-2016-2037, CVE-2019-14866.
Switched to .bz2 tarball.
Added hashes provided by upstream and license hash.
Release notes:
https://lists.gnu.org/archive/html/info-gnu/2019-11/msg00002.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:30:05 +01:00
Bernd Kuhls
bcb6d0057f
package/gnupg2: bump version to 2.2.19
...
Release notes:
- 2.2.18
https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.html
- 2.2.19
https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000443.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-05 21:29:22 +01:00
Fabrice Fontaine
db23093b28
package/wavemon: bump to version 0.9.1
...
Drop patch (already in version)
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2020-01-05 17:22:02 +01:00
Fabrice Fontaine
0715209aa7
package/spi-tools: bump to version 0.8.4
...
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2020-01-05 17:21:59 +01:00
Fabrice Fontaine
f77037ab2c
package/mosquitto: drop patch
...
Drop patch (refused by upstream) and use CLIENT_STATIC_LDADD that has
been added in version 1.6.8 with
6bde209799
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2020-01-05 17:20:43 +01:00
Romain Naour
b64b548289
toolchain/toolchain-external: update Arm AArch64 toolchain 9.2-2019.12
...
Update to gcc 9.2.1, gdb 8.3.0, binutils 2.33.1.
See "Release Note":
https://developer.arm.com/open-source/gnu-toolchain/gnu-a/downloads#
Tested with qemu_aarch64_virt_defconfig.
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:30:26 +01:00
Romain Naour
e1a6deef25
toolchain/toolchain-external: update Arm ARM toolchain 9.2-2019.12
...
Update to gcc 9.2.1, gdb 8.3.0, binutils 2.33.1.
See "Release Note":
https://developer.arm.com/open-source/gnu-toolchain/gnu-a/downloads#
Tested with qemu_arm_vexpress_defconfig.
Signed-off-by: Romain Naour <romain.naour@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:30:24 +01:00
Bernd Kuhls
5cf68c8f79
package/freeswitch: bump version to 1.10.2
...
Rebased patch 0001.
Release notes:
https://github.com/signalwire/freeswitch/releases/tag/v1.10.2
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:28:29 +01:00
Bernd Kuhls
38510af3fb
package/ffmpeg: bump version to 4.2.2
...
Changelog:
http://git.videolan.org/?p=ffmpeg.git;a=blob;f=Changelog;h=9c992b5c3e3995a0e8f3316b3087205196dc6403;hb=refs/heads/release/4.2
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:28:11 +01:00
Bernd Kuhls
2dd2df43db
package/samba4: security bump version to 4.11.4
...
Version 4.11.3 fixes
CVE-2019-14861: Samba AD DC zone-named record Denial of Service in DNS
management server (dnsserver).
CVE-2019-14870: DelegationNotAllowed not being enforced in protocol
transition on Samba AD DC.
Changelog:
https://www.samba.org/samba/history/samba-4.11.3.html
https://www.samba.org/samba/history/samba-4.11.4.html
Removed patches applied upstream, rebased patch 0002.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:21:41 +01:00
Bernd Kuhls
6038c3232a
package/exim: bump version to 4.93.0.3
...
Removed 0004-Fix-uClibc-build.patch, committed upstream
https://git.exim.org/exim.git/commitdiff/ec5bf0b83235d01ad0b2865d1819a603441f50f2
Renumbered remaining patches.
Added hashes provided by upstream.
Explicitly disabled DANE after upstream enabled it:
https://git.exim.org/exim.git/commitdiff/59c0959a36649c4554bd0f18f2c2e74571ed41eb#patch3
Use new TLS options:
https://git.exim.org/exim.git/commitdiff/01603eec64d42431f182b33008206facfc7f800e#patch1
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:21:22 +01:00
Bernd Kuhls
e3d8097272
package/dovecot-pigeonhole: bump version to 0.5.9
...
Release notes:
https://dovecot.org/pipermail/dovecot-news/2019-December/000424.html
https://dovecot.org/pipermail/dovecot-news/2019-October/000420.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:10:02 +01:00
Bernd Kuhls
8ff8d4fbd8
package/dovecot: bump version to 2.3.9.2
...
Release notes:
https://dovecot.org/pipermail/dovecot-news/2019-October/000419.html
https://dovecot.org/pipermail/dovecot-news/2019-December/000423.html
https://dovecot.org/pipermail/dovecot-news/2019-December/000425.html
https://dovecot.org/pipermail/dovecot-news/2019-December/000427.html
Please note that according to
https://security-tracker.debian.org/tracker/CVE-2019-19722
CVE-2019-19722 fixes a bug introduced in 2.3.9 so backporting this patch
to older buildroot branches is not necessary.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2020-01-04 16:09:57 +01:00