Commit Graph

173138 Commits

Author SHA1 Message Date
Marek Mahut
938c15b94a openjpeg: CVE-2019-12973 #64182
(cherry picked from commit 0596ac9667)
2019-07-20 09:38:00 +02:00
Marek Mahut
d7ab443306 libxslt: CVE-2019-13118 #64661
(cherry picked from commit 9a6bd59111)
2019-07-20 09:28:58 +02:00
Marek Mahut
64079b9033 libxslt: CVE-2019-13117 #64661
(cherry picked from commit 3aefa76106)
2019-07-20 09:28:16 +02:00
Graham Christensen
5443be5bd0 Merge pull request #64735 from risicle/ris-zeromq-4.3.2-r19.03
[r19.03] zeromq: 4.3.1 -> 4.3.2, fixing CVE-2019-13132
2019-07-18 17:31:42 -04:00
Vladimír Čunát
be61b5bd1a Merge branch 'release-19.03' into staging-19.03 2019-07-15 18:44:13 +02:00
Eelco Dolstra
e2ad04c513 nixFlakes: 2.3pre20190612_06010ea -> 2.3pre20190712_aa82f8b
(cherry picked from commit 31c38894c9)
2019-07-15 16:21:47 +02:00
taku0
2143d047d4 nss: 3.44 -> 3.44.1
(cherry picked from commit 442fd85db6)
Fresh nss will be needed for further Firefox updates; /cc PR #64742
2019-07-15 15:00:38 +02:00
Will Dietz
1015f72ff1 nss: 3.43 -> 3.44
(cherry picked from commit 979970a4cd)
2019-07-15 14:59:37 +02:00
Will Dietz
ddcd81eee1 nss: 3.42.1 -> 3.43
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.43_release_notes
(cherry picked from commit 354ccb2052)
2019-07-15 14:59:24 +02:00
Robin Gloster
3cd79ef30f Merge pull request #64638 from johanot/jira-8.1.2
atlassian-jira: 8.1.0 -> 8.1.2
2019-07-15 12:26:13 +00:00
Mario Rodas
198a6bd91c python37: fix distutils C++ patch (PR #64758)
Update distutils patch to the upstream changes.
See: 6c0e0d141a

(cherry picked from commit 7094a1af0c)
2019-07-15 14:00:12 +02:00
Michael Raskin
0d0cb247ff Merge pull request #64745 from risicle/ris-squid-CVE-2019-13345-r19.03
[r19.03] squid, squid4: add patches fixing CVE-2019-13345
2019-07-15 10:35:14 +00:00
Robert Scott
db682731bc squid: add patch fixing CVE-2019-13345 2019-07-14 22:30:33 +01:00
Robert Scott
c62d44b9e1 squid4: add patch fixing CVE-2019-13345 2019-07-14 22:30:22 +01:00
worldofpeace
f4fcdac99f Merge pull request #64712 from risicle/ris-cf-cli-6.43.0-r19.03
[r19.03] cloudfoundry-cli: 6.41.0 -> 6.43.0, fixing CVE-2019-3781
2019-07-14 14:01:06 -04:00
worldofpeace
c0339a7b39 Merge pull request #64375 from das-g/release-19.03_keybase-backport
keybase{,-gui}: 3.0.0 -> 4.1.0
2019-07-14 12:30:03 -04:00
Robert Scott
f9a62b7c8d zeromq: 4.3.1 -> 4.3.2 2019-07-14 16:49:56 +01:00
Orivej Desh
30548e9654 dmenu: fix crash with XMODIFIERS
Fixes #59625

(cherry picked from commit 1f16d0496c)
2019-07-14 13:53:01 +00:00
Graham Christensen
c31b7402b1 Merge pull request #64724 from risicle/ris-redis-5.0.5-r19.03
[r19.03] redis: 5.0.3 -> 5.0.5, fixing CVE-2019-10192 & CVE-2019-10193
2019-07-14 05:53:01 -07:00
Tim Steinbach
a6598a6c86 linux: 5.1.17 -> 5.1.18 2019-07-14 08:15:49 -04:00
Tim Steinbach
b09ee75726 linux: 4.19.58 -> 4.19.59 2019-07-14 08:15:48 -04:00
Robert Scott
7e36e7f652 redis: 5.0.3 -> 5.0.5
fixing CVE-2019-10192 and CVE-2019-10193
2019-07-14 11:28:33 +01:00
Vladimír Čunát
cf16778cd6 knot-resolver: fixup build on Darwin
I'm not 100% sure how we handle purity there, but so far it seems that
this change is only needed on 19.03 branch.
2019-07-14 09:54:38 +02:00
Vladimír Čunát
68d032a46f Merge #64372: wavpack: Vulnerability roundup 71
(cherry picked from commit 620ad0b969)
2019-07-14 09:48:05 +02:00
Robert Scott
540d9a93d6 cloudfoundry-cli: 6.41.0 -> 6.43.0
fixing CVE-2019-3781
2019-07-13 19:06:43 +01:00
worldofpeace
e726e8291b pantheon.elementary-icon-theme: 5.0.3 -> 5.0.4
https://github.com/elementary/icons/releases/tag/5.0.4
(cherry picked from commit 1aaa9ba3d8)
2019-07-13 10:59:09 -04:00
Peter Simons
e8e1eeccb8 Merge #64538: gnupg: 2.2.16 -> 2.2.17 (security)
(cherry picked from commit 84e3370358)
CVE-2019-13050 #64658.  The other changes don't sound too intrusive:
https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html
2019-07-13 15:33:23 +02:00
Jan Tojnar
88cb463a3b libsForQt5.qtkeychain: add libsecret support
qtkeychain uses pkg-config to detect whether libsecret is available,
otherwise it just builds a stub object file.

We need libsecret support to allow nextcloud-client storing passwords
on Freedesktop platforms.

I also fixed the Darwin dependencies not being used with Qt5,
even though the build did not complain.

(cherry picked from commit 48316aeec1)
Signed-off-by: Maximilian Bosch <maximilian@mbosch.me>
2019-07-13 12:17:35 +02:00
Vladimír Čunát
fb30decc1d Merge #64272: powerdns: 4.1.9 -> 4.1.10 (DoS security)
CVE-2019-10162, CVE-2019-10163

(cherry picked from commit 64cb53dc01)
2019-07-13 11:06:50 +02:00
Vladimír Čunát
63963b8f34 Merge #64690: thunderbird*: 60.7.2 -> 60.8.0 (security)
(cherry picked from commit e87ed4cef3)
2019-07-13 10:02:20 +02:00
Vladimír Čunát
1dddf80571 Merge #64577: firefox-bin: 67.0.4 -> 68.0 (security)
(cherry picked from commit dc121c754e)
2019-07-13 10:02:09 +02:00
Vladimír Čunát
45b4e23a41 Merge #64679: glib: fix CVE-2019-13012 (in staging-19.03) 2019-07-13 09:17:04 +02:00
Vladimír Čunát
f7bd8d6bd8 Merge branch 'release-19.03' into staging-19.03 2019-07-13 09:16:54 +02:00
worldofpeace
35e28b488f glib: fix CVE-2019-13012
CVE-2019-13012 Description:

The keyfile settings backend in GLib before 2.59.1 creates directories
using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and
files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE,
G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL).
Consequently, it does not properly restrict directory (and file) permissions.
Instead, for directories, 0777 permissions are used; for files, default file
permissions are used.

Patch Summary:

Changes the permissions when a directory is created,
using 700 instead 777 in gio/gkeyfilesettingsbackend.c
and changes test to run in a temp directory in gio/tests/gsettings.c.

Upstream Issue: https://gitlab.gnome.org/GNOME/glib/issues/1658
Upstream MR: https://gitlab.gnome.org/GNOME/glib/merge_requests/604

Fixes #64657
2019-07-12 16:27:34 -04:00
Maximilian Bosch
5f707e8e06 mautrix-whatsapp: 2019-02-24 -> 2019-07-04
Bump to the latest revision of `mautrix-whatsapp` to regain
compatibility with matrix-synapse 0.99.5.

Please note that it was necessary to alter some of the sources in
`deps.nix`, please read the comment at the top of the file for further
information.

(cherry picked from commit b86a3e46b3)
2019-07-12 18:27:59 +02:00
Vladimír Čunát
9354bc967d Merge knot-resolver: 3.2.1 -> 4.1.0 (security)
19.03: I'm really sorry to pull a "major" update, but the security
fixes are rather hard to backport correctly.  Please contact me in case
you run into problems when upgrading.
2019-07-12 15:53:22 +02:00
Pascal Bach
d10e680168 gitlab-runner: 11.11.2 -> 12.0.2
12.0.1 fixes an issue with git submodule fetching
12.0.2 fixes an issue with concurrent updated

(cherry picked from commit e928aa6f50)
2019-07-12 12:39:48 +02:00
xrelkd
88f069e2d8 youtube-dl: 2019.07.02 -> 2019.07.12
(cherry picked from commit 345843601a)
2019-07-11 23:54:41 -04:00
Johan Thomsen
9d1f4e5756 atlassian-jira: 8.1.0 -> 8.1.2 2019-07-11 19:31:23 +02:00
R. RyanTM
f0fdbd89ae python37Packages.aiorpcx: 0.17.0 -> 0.18.3
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/python3.7-aiorpcx/versions

(cherry picked from commit 54fa84b988)

Required by electrum 3.3.7
2019-07-11 16:15:38 +02:00
worldofpeace
9fde0140fc pantheon.wingpanel-indicator-session: 2.2.3 -> 2.2.4
https://github.com/elementary/wingpanel-indicator-session/releases/tag/2.2.4
(cherry picked from commit def7d562e0)
2019-07-11 10:07:22 -04:00
Will Dietz
ecc64b374b electrum: 3.3.6 -> 3.3.7
(cherry picked from commit fcd6773c4c)
2019-07-10 20:46:26 +02:00
Joachim Fasting
2f8c3024ff tor-browser-bundle-bin: 8.5.3 -> 8.5.4
(cherry picked from commit 5f6b008eb5)
2019-07-10 20:46:07 +02:00
SLNOS
69e48a1acb firefoxPackages.tor-browser: 8.5.2 -> 8.5.4
(cherry picked from commit 279a001062)
2019-07-10 19:08:59 +02:00
Vladimír Čunát
c5d39d8962 knot-resolver: 4.0.0 -> 4.1.0 (security)
https://lists.nic.cz/pipermail/knot-resolver-users/2019/000189.html
Fixes DNS spoofing problems: CVE-2019-10190 CVE-2019-10191
but also minor things, adds new features, etc.
In particular aarch64 should work now, at least as long as not using
some lua library that suffers from the same problem with lightuserdata,
e.g. cqueues does suffer from this.

(cherry picked from commit f15625a6c0)
2019-07-10 18:16:48 +02:00
Vladimír Čunát
26053855bb knot-resolver: fixup the build after cherry-picking 2019-07-10 18:16:48 +02:00
Vladimír Čunát
6c233963dc knot-resolver: 3.2.1 -> 4.0.0
https://lists.nic.cz/pipermail/knot-resolver-users/2019/000136.html

Similar commit worked fine for me, including the nixos service.
I'd like to still improve the service to support easy passing of sockets
to http module.

(cherry picked from commit 9efdd2e434)
I'm really sorry to pull a "major" update, but the upcoming security
fixes are rather hard to backport correctly.  Please contact me in case
you run into problems when upgrading.
2019-07-10 18:15:48 +02:00
Tim Steinbach
021f94354c linux: 5.1.16 -> 5.1.17 2019-07-10 07:51:10 -04:00
Tim Steinbach
a9a0f33500 linux: 4.9.184 -> 4.9.185 2019-07-10 07:51:10 -04:00
Tim Steinbach
0f617ca2e8 linux: 4.4.184 -> 4.4.185 2019-07-10 07:51:09 -04:00