Skip to content
Snippets Groups Projects
  1. May 10, 2021
    • W. Michael Petullo's avatar
      openldap: update to 2.4.58 · f200ccd6
      W. Michael Petullo authored
      
      Signed-off-by: default avatarW. Michael Petullo <mike@flyn.org>
      f200ccd6
    • Daniel Golle's avatar
      lvm2: update to version 2.03.12 · dc27d43f
      Daniel Golle authored
      
      Two notable changes are devices file and metadata based autoactivation.
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      dc27d43f
    • Daniel Golle's avatar
      exim: update to version 4.94.2 · c241cb12
      Daniel Golle authored
      
      Several exploitable vulnerabilities in Exim were reported to us and are
      fixed.
      Local vulnerabilities
      - CVE-2020-28007: Link attack in Exim's log directory
      - CVE-2020-28008: Assorted attacks in Exim's spool directory
      - CVE-2020-28014: Arbitrary PID file creation
      - CVE-2020-28011: Heap buffer overflow in queue_run()
      - CVE-2020-28010: Heap out-of-bounds write in main()
      - CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
      - CVE-2020-28016: Heap out-of-bounds write in parse_fix_phrase()
      - CVE-2020-28015: New-line injection into spool header file (local)
      - CVE-2020-28012: Missing close-on-exec flag for privileged pipe
      - CVE-2020-28009: Integer overflow in get_stdinput()
      Remote vulnerabilities
      - CVE-2020-28017: Integer overflow in receive_add_recipient()
      - CVE-2020-28020: Integer overflow in receive_msg()
      - CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
      - CVE-2020-28021: New-line injection into spool header file (remote)
      - CVE-2020-28022: Heap out-of-bounds read and write in extract_option()
      - CVE-2020-28026: Line truncation and injection in spool_read_header()
      - CVE-2020-28019: Failure to reset function pointer after BDAT error
      - CVE-2020-28024: Heap buffer underflow in smtp_ungetc()
      - CVE-2020-28018: Use-after-free in tls-openssl.c
      - CVE-2020-28025: Heap out-of-bounds read in pdkim_finish_bodyhash()
      
      The update to 4.94.2 also integrates a fix for a printf format issue
      previously addressed by a local patch which is removed.
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      c241cb12
    • Daniel Golle's avatar
      auc: support queue_position status from server · 5b7ff1ad
      Daniel Golle authored
      
      Display position in queue while waiting for build.
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      5b7ff1ad
  2. May 08, 2021
  3. May 07, 2021
  4. May 06, 2021
  5. May 05, 2021
  6. May 04, 2021
  7. May 03, 2021
  8. May 02, 2021
  9. May 01, 2021
  10. Apr 30, 2021
Loading