Skip to content
  1. Sep 08, 2022
  2. Sep 07, 2022
    • Daniel Golle's avatar
      gnunet: update to version 0.17.5 · 6d49ad9e
      Daniel Golle authored
      
      
      Beware that switching to the new major version 0.17.x results in
      incompatibility with clients still running 0.16.x.
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      6d49ad9e
    • Daniel Golle's avatar
      libp11: update to version 0.4.12 · d3b50744
      Daniel Golle authored
      
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      d3b50744
    • Daniel Golle's avatar
      rtpmidid: update to snapshot of 2022-07-07 · 1cd5d55c
      Daniel Golle authored
      
      
       ae98df0 0xF1 MIDI Quarter Frame is 2 bytes long
       eab5cd8 Added more MIDI messages and comments
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      1cd5d55c
    • Daniel Golle's avatar
      libinput: update to version 1.19.4 · b95dbe41
      Daniel Golle authored
      This release includes a fix for CVE-2022-1215, a format string
      vulnerabilty in the evdev device handling. For details, see
      https://gitlab.freedesktop.org/libinput/libinput/-/issues/752
      
      
      
      Peter Hutterer (2):
            evdev: strip the device name of format directives
            libinput 1.19.4
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      b95dbe41
    • Daniel Golle's avatar
      libevdev: update to version 1.13.0 · 630f5b16
      Daniel Golle authored
      
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      630f5b16
    • Daniel Golle's avatar
      postgresql: update to version 14.5 · ead096d6
      Daniel Golle authored
      Release date: 2022-08-11
      Adresses CVE-2022-2625.
      For more details, please see the release notes[1].
      
      [1]: https://www.postgresql.org/docs/release/14.5/
      
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      ead096d6
    • Daniel Golle's avatar
      pcsc-lite: update to version 1.9.8 · db667b5b
      Daniel Golle authored
      
      
      1.9.8: Ludovic Rousseau
      11 June 2022
      - Install install_spy.sh & uninstall_spy.sh scripts in docdir
      - SCardTransmit(): do not fail if receive buffer is "too large"
      - SCardControl(): do not fail if receive buffer is "too large"
      - fix some memory leaks on shutdown
      - use a better random number generator
      - Some other minor improvements
      
      1.9.7: Ludovic Rousseau
      13 May 2022
      - disable strict compilation by default
      - fix 3 warnings
      
      1.9.6: Ludovic Rousseau
      11 May 2022
      - do not fail reader removal in some specific cases (USB/Thunderbolt port)
      - improve documentation regarding /etc/reader.conf.d/
      - SCardGetStatusChange: speedup the case DISABLE_AUTO_POWER_ON
      - configure:
        . add --disable-strict option
         By default the compiler arguments are now:
         -Wall -Wextra -Wno-unused-parameter -Werror ${CFLAGS}
        . fail if flex is not found
      - fix different data races
      - pcscdaemon: -v displays internal constants values:
        MAX_READERNAME & PCSCLITE_MAX_READERS_CONTEXTS
      - Some other minor improvements
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      db667b5b
    • Daniel Golle's avatar
      exim: update to version 4.96 · f2763b95
      Daniel Golle authored
      
      
      Exim version 4.96
      -----------------
      
      JH/01 Move the wait-for-next-tick (needed for unique message IDs) from
            after reception to before a subsequent reception.  This should
            mean slightly faster delivery, and also confirmation of reception
            to senders.
      
      JH/02 Move from using the pcre library to pcre2.  The former is no longer
            being developed or supported (by the original developer).
      
      JH/03 Constification work in the filters module required a major version
            bump for the local-scan API.  Specifically, the "headers_charset"
            global which is visible via the API is now const and may therefore
            not be modified by local-scan code.
      
      JH/04 Fix ClamAV TCP use under FreeBSD. Previously the OS-specific shim for
            sendfile() didi not account for the way the ClamAV driver code called it.
      
      JH/05 Bug 2819: speed up command-line messages being read in.  Previously a
            time check was being done for every character; replace that with one
            per buffer.
      
      JH/06 Bug 2815: Fix ALPN sent by server under OpenSSL.  Previously the string
            sent was prefixed with a length byte.
      
      JH/07 Change the SMTP feature name for pipelining connect to be compliant with
            RFC 5321.  Previously Dovecot (at least) would log errors during
            submission.
      
      JH/08 Remove stripping of the binaries from the FreeBSD build.  This was added
            in 4.61 without a reason logged. Binaries will be bigger, which might
            matter on diskspace-constrained systems, but debug is easier.
      
      JH/09 Fix macro-definition during "-be" expansion testing.  The move to
            write-protected store for macros had not accounted for these runtime
            additions; fix by removing this protection for "-be" mode.
      
      JH/10 Convert all uses of select() to poll().  FreeBSD 12.2 was found to be
            handing out large-numbered file descriptors, violating the usual Unix
            assumption (and required by Posix) that the lowest possible number will be
            allocated by the kernel when a new one is needed.  In the daemon, and any
            child procesees, values higher than 1024 (being bigger than FD_SETSIZE)
            are not useable for FD_SET() [and hence select()] and overwrite the stack.
            Assorted crashes happen.
      
      JH/11 Fix use of $sender_host_name in daemon process.  When used in certain
            main-section options or in a connect ACL, the value from the first ever
            connection was never replaced for subsequent connections.  Found by
            Wakko Warner.
      
      JH/12 Bug 2838: Fix for i32lp64 hard-align platforms. Found for SPARC Linux,
            though only once PCRE2 was introduced: the memory accounting used under
            debug offset allocations by an int, giving a hard trap in early startup.
            Change to using a size_t.  Debug and fix by John Paul Adrian Glaubitz.
      
      JH/13 Bug 2845: Fix handling of tls_require_ciphers for OpenSSL when a value
            with underbars is given.  The write-protection of configuration introduced
            in 4.95 trapped when normalisation was applied to an option not needing
            expansion action.
      
      JH/14 Bug 1895: TLS: Deprecate RFC 5114 Diffie-Hellman parameters.
      
      JH/15 Fix a resource leak in *BSD.  An off-by-one error resulted in the daemon
            failing to close the certificates directory, every hour or any time it
            was touched.
      
      JH/16 Debugging initiated by an ACL control now continues through into routing
            and transport processes.  Previously debugging stopped any time Exim
            re-execs, or for processing a queued message.
      
      JH/17 The "expand" debug selector now gives more detail, specifically on the
            result of expansion operators and items.
      
      JH/18 Bug 2751: Fix include_directory in redirect routers.  Previously a
            bad comparison between the option value and the name of the file to
            be included was done, and a mismatch was wrongly identified.
            4.88 to 4.95 are affected.
      
      JH/19 Support for Berkeley DB versions 1 and 2 is withdrawn.
      
      JH/20 When built with NDBM for hints DB's check for nonexistence of a name
            supplied as the db file-pair basename.  Previously, if a directory
            path was given, for example via the autoreply "once" option, the DB
            file.pag and file.dir files would be created in that directory's
            parent.
      
      JH/21 Remove the "allow_insecure_tainted_data" main config option and the
            "taint" log_selector.  These were previously deprecated.
      
      JH/22 Fix static address-list lookups to properly return the matched item.
            Previously only the domain part was returned.
      
      JH/23 Bug 2864: FreeBSD: fix transport hang after 4xx/5xx response. Previously
            the call into OpenSSL to send a TLS Close was being repeated; this
            resulted in the library waiting for the peer's Close.  If that was never
            sent we waited forever.  Fix by tracking send calls.
      
      JH/24 The ${run} expansion item now expands its command string elements after
            splitting.  Previously it was before; the new ordering makes handling
            zero-length arguments simpler.  The old ordering can be obtained by
            appending a new option "preexpand", after a comma, to the "run".
      
      JH/25 Taint-check exec arguments for transport-initiated external processes.
            Previously, tainted values could be used.  This affects "pipe", "lmtp" and
            "queryprogram" transport, transport-filter, and ETRN commands.
            The ${run} expansion is also affected: in "preexpand" mode no part of
            the command line may be tainted, in default mode the executable name
            may not be tainted.
      
      JH/26 Fix CHUNKING on a continued-transport.  Previously the usabliility of
            the the facility was not passed across execs, and only the first message
            passed over a connection could use BDAT; any further ones using DATA.
      
      JH/27 Support the PIPECONNECT facility in the smtp transport when the helo_data
            uses $sending_ip_address and an interface is specified.
            Previously any use of the local address in the EHLO name disabled
            PIPECONNECT, the common case being to use the rDNS of it.
      
      JH/28 OpenSSL: fix transport-required OCSP stapling verification under session
            resumption. Previously verify failed because no certificate status is
            passed on the wire for the restarted session. Fix by using the recorded
            ocsp status of the stored session for the new connection.
      
      JH/29 TLS resumption: the key for session lookup in the client now includes
            more info that a server could potentially use in configuring a TLS
            session, avoiding oferring mismatching sessions to such a server.
            Previously only the server IP was used.
      
      JH/30 Fix string_copyn() for limit greater than actual string length.
            Previously the copied amount was the limit, which could result in a
            overlapping memcpy for newly allocated destination soon after a
            source string shorter than the limit.  Found/investigated  by KM.
      
      JH/31 Bug 2886: GnuTLS: Do not free the cached creds on transport connection
            close; it may be needed for a subsequent connection.  This caused a
            SEGV on primary-MX defer.  Found/investigated by Gedalya & Andreas.
      
      JH/32 Fix CHUNKING for a second message on a connection when the first was
            rejected.  Previously we did not reset the chunking-offered state, and
            erroneously rejected the BDAT command.  Investigation help from
            Jesse Hathaway.
      
      JH/33 Fis ${srs_encode ...} to handle an empty sender address, now returning
            an empty address.  Previously the expansion returned an error.
      
      HS/01 Bug 2855: Handle a v4mapped sender address given us by a frontending
            proxy.  Previously these were misparsed, leading to paniclog entries.
      
      Also contains commit 51be321b27 "Fix PAM auth. Bug 2813" addressing
      CVE-2022-37451.
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      f2763b95
    • Daniel Golle's avatar
      gpgme: update to version 1.18.0 · 00bfb4f1
      Daniel Golle authored
      
      
       Noteworthy changes in version 1.18.0 (2022-08-10)
       -------------------------------------------------
      
       * New keylist mode to force refresh via external methods.  [T5951]
       * The keylist operations now create an import result to report the
         result of the locate keylist modes.  [T5951]
       * core: Return BAD_PASSPHRASE error code on symmetric decryption
         failure.  [T5939]
       * cpp, qt: Do not export internal symbols anymore.  [T5906]
       * cpp, qt: Support revocation of own OpenPGP keys.  [T5904]
       * qt: The file name of (signed and) encrypted data can now be set.  [T6056]
       * cpp, qt: Support setting the primary user ID.  [T5938]
       * python: Fix segv(NULL) when inspecting contect after exeception.  [T6060]
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      00bfb4f1
    • Daniel Golle's avatar
      cryptsetup: update to version 2.5.0 · 80439f80
      Daniel Golle authored
      Update to new major release of cryptsetup. For details, please see
      the release notes[1].
      
      [1]: https://cdn.kernel.org/pub/linux/utils/cryptsetup/v2.5/v2.5.0-ReleaseNotes
      
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      80439f80
    • Daniel Golle's avatar
      lvm2: update to release 2.03.16 · 4e70f5ca
      Daniel Golle authored
      
      
      Mostly bug fixes and minor improvements.
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      4e70f5ca
    • Michael Heimpold's avatar
      Merge pull request #19321 from mhei/php8-update-8.1.10 · ebda9516
      Michael Heimpold authored
      php8: update to 8.1.10
      ebda9516
    • Michael Heimpold's avatar
      Merge pull request #19250 from mhei/bugfix19099 · 4155774e
      Michael Heimpold authored
      squid: fix compilation with libxml (refs #19099)
      4155774e