| Commit message (Expand) | Author | Age | Files | Lines |
* | Wed Jan 31 21:19:19 UTC 2024...ap/nvme-cli-2.7.1-x86_64-1.txz: Upgraded.
l/libnvme-1.7.1-x86_64-1.txz: Added.
This is required by nvme-cli.
l/pipewire-1.0.2-x86_64-1.txz: Upgraded.
n/curl-8.6.0-x86_64-1.txz: Upgraded.
n/libmilter-8.18.1-x86_64-1.txz: Upgraded.
extra/sendmail/sendmail-8.18.1-x86_64-1.txz: Upgraded.
sendmail through 8.17.2 allows SMTP smuggling in certain configurations.
Remote attackers can use a published exploitation technique to inject e-mail
messages with a spoofed MAIL FROM address, allowing bypass of an SPF
protection mechanism. This occurs because sendmail supports <LF>.<CR><LF>
but some other popular e-mail servers do not. This is resolved in 8.18 and
later versions with 'o' in srv_features.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-51765
(* Security fix *)
extra/sendmail/sendmail-cf-8.18.1-noarch-1.txz: Upgraded.
20240131211919 | Patrick J Volkerding | 2024-01-31 | 1 | -3/+2 |
* | Tue Jun 6 20:26:59 UTC 2023...a/kernel-firmware-20230531_fc90c59-noarch-1.txz: Upgraded.
a/kernel-generic-6.1.32-x86_64-1.txz: Upgraded.
a/kernel-huge-6.1.32-x86_64-1.txz: Upgraded.
a/kernel-modules-6.1.32-x86_64-1.txz: Upgraded.
d/gcc-13.1.0-x86_64-2.txz: Rebuilt.
d/gcc-g++-13.1.0-x86_64-2.txz: Rebuilt.
d/gcc-gdc-13.1.0-x86_64-2.txz: Rebuilt.
d/gcc-gfortran-13.1.0-x86_64-2.txz: Rebuilt.
d/gcc-gm2-13.1.0-x86_64-2.txz: Added.
d/gcc-gnat-13.1.0-x86_64-2.txz: Rebuilt.
d/gcc-go-13.1.0-x86_64-2.txz: Rebuilt.
d/gcc-objc-13.1.0-x86_64-2.txz: Rebuilt.
d/kernel-headers-6.1.32-x86-1.txz: Upgraded.
d/libtool-2.4.7-x86_64-5.txz: Rebuilt.
Recompiled to update embedded GCC version number.
k/kernel-source-6.1.32-noarch-1.txz: Upgraded.
kde/calligra-3.2.1-x86_64-30.txz: Rebuilt.
Recompiled against poppler-23.06.0.
kde/cantor-23.04.1-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.06.0.
kde/kfilemetadata-5.106.0-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.06.0.
kde/kile-2.9.93-x86_64-25.txz: Rebuilt.
Recompiled against poppler-23.06.0.
kde/kitinerary-23.04.1-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.06.0.
kde/krita-5.1.5-x86_64-10.txz: Rebuilt.
Recompiled against poppler-23.06.0.
kde/okteta-0.26.11-x86_64-1.txz: Upgraded.
kde/okular-23.04.1-x86_64-2.txz: Rebuilt.
Recompiled against poppler-23.06.0.
l/enchant-2.5.0-x86_64-1.txz: Upgraded.
l/gtk4-4.10.4-x86_64-1.txz: Upgraded.
l/mozilla-nss-3.90-x86_64-1.txz: Upgraded.
l/openexr-3.1.8-x86_64-1.txz: Upgraded.
l/poppler-23.06.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
l/qtkeychain-0.14.1-x86_64-1.txz: Upgraded.
n/krb5-1.21-x86_64-1.txz: Upgraded.
n/ntp-4.2.8p17-x86_64-1.txz: Upgraded.
This is a bugfix release.
n/postfix-3.8.1-x86_64-1.txz: Upgraded.
x/xorg-server-xwayland-23.1.2-x86_64-1.txz: Upgraded.
x/xorgproto-2023.1-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-114.0-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/114.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2023-20/
https://www.cve.org/CVERecord?id=CVE-2023-34414
https://www.cve.org/CVERecord?id=CVE-2023-34415
https://www.cve.org/CVERecord?id=CVE-2023-34416
https://www.cve.org/CVERecord?id=CVE-2023-34417
(* Security fix *)
xfce/xfce4-panel-profiles-1.0.14-x86_64-1.txz: Upgraded.
extra/sendmail/sendmail-8.17.2-x86_64-2.txz: Rebuilt.
Recompiled without -DUSE_EAI or ICU libraries as this experimental option
is still leading to regressions.
extra/sendmail/sendmail-cf-8.17.2-noarch-2.txz: Rebuilt.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.
20230606202659 | Patrick J Volkerding | 2023-06-07 | 1 | -2/+2 |
* | Sun Jun 4 19:16:13 UTC 2023...l/ocl-icd-2.3.2-x86_64-1.txz: Upgraded.
n/libmilter-8.17.2-x86_64-1.txz: Upgraded.
x/egl-wayland-1.1.12-x86_64-1.txz: Upgraded.
x/libdmx-1.1.5-x86_64-1.txz: Upgraded.
x/xrdb-1.2.2-x86_64-1.txz: Upgraded.
x/xscope-1.4.4-x86_64-1.txz: Upgraded.
x/xtrans-1.5.0-noarch-1.txz: Upgraded.
x/xwd-1.0.9-x86_64-1.txz: Upgraded.
extra/sendmail/sendmail-8.17.2-x86_64-1.txz: Upgraded.
This is a bugfix release.
extra/sendmail/sendmail-cf-8.17.2-noarch-1.txz: Upgraded.
20230604191613 | Patrick J Volkerding | 2023-06-04 | 1 | -1/+1 |
* | Tue Aug 30 19:39:30 UTC 2022...a/cryptsetup-2.5.0-x86_64-3.txz: Rebuilt.
rc.luks: use --batch-mode when creating encrypted swap.
Thanks to Markus Wiesner.
a/sysvinit-3.05-x86_64-1.txz: Upgraded.
ap/vim-9.0.0334-x86_64-1.txz: Upgraded.
Fixed use after free.
Thanks to marav for the heads-up.
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3016
(* Security fix *)
kde/digikam-7.8.0-x86_64-1.txz: Upgraded.
kde/fcitx5-configtool-5.0.15-x86_64-1.txz: Upgraded.
kde/umbrello-22.08.0-x86_64-2.txz: Rebuilt.
Recompiled against kdevelop-22.08.0. Thanks to th_r.
x/fcitx5-5.0.19-x86_64-1.txz: Upgraded.
x/fcitx5-chinese-addons-5.0.15-x86_64-1.txz: Upgraded.
x/libime-1.0.14-x86_64-1.txz: Upgraded.
xap/NetworkManager-openvpn-1.10.0-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-104.0.1-x86_64-1.txz: Upgraded.
This is a bugfix release.
For more information, see:
https://www.mozilla.org/en-US/firefox/104.0.1/releasenotes/
xap/vim-gvim-9.0.0334-x86_64-1.txz: Upgraded.
extra/sendmail/sendmail-8.17.1-x86_64-5.txz: Rebuilt.
Patched sendmail.h to fix SASL auth. Thanks to af7567.
Build without -DUSE_EAI (which is evidently considered experimental) since
the option breaks the vacation binary. Thanks to bitfuzzy and HQuest.
It is possible that this could work but requires additional options. I found
this in the ChangeLog for the SUSE rpm:
Experimental support for SMTPUTF8 (EAI, see RFC 6530-6533) is available
when using the compile time option USE_EAI (see also
devtools/Site/site.config.m4.sample for other required settings) and the cf
option SMTPUTF8. If a mail submission via the command line requires the
use of SMTPUTF8, e.g., because a header uses UTF-8 encoding, but the
addresses on the command line are all ASCII, then the new option -U must be
used, and the cf option SMTPUTF8 must be set in submit.cf.
Any assistance with getting -DUSE_EAI working properly would be appreciated.
extra/sendmail/sendmail-cf-8.17.1-noarch-5.txz: Rebuilt.
20220830193930 | Patrick J Volkerding | 2022-08-31 | 1 | -1/+1 |
* | Tue Aug 23 19:27:56 UTC 2022...ap/inxi-3.3.21_1-noarch-1.txz: Upgraded.
d/ccache-4.6.2-x86_64-1.txz: Upgraded.
d/parallel-20220822-noarch-1.txz: Upgraded.
kde/kleopatra-22.08.0-x86_64-2.txz: Rebuilt.
Patched to build with gpgme-1.18.0.
l/babl-0.1.94-x86_64-1.txz: Upgraded.
l/hunspell-1.7.1-x86_64-1.txz: Upgraded.
Fixed invalid read operation in SuggestMgr::leftcommonsubstring
in suggestmgr.cxx.
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16707
(* Security fix *)
l/libqalculate-4.3.0-x86_64-1.txz: Upgraded.
n/ethtool-5.19-x86_64-1.txz: Upgraded.
n/gpgme-1.18.0-x86_64-1.txz: Upgraded.
n/nghttp2-1.49.0-x86_64-1.txz: Upgraded.
x/ibus-1.5.27-x86_64-1.txz: Upgraded.
x/libglvnd-1.5.0-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-104.0-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/104.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2022-33/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38472
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38473
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38474
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38475
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38477
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38478
(* Security fix *)
xap/mozilla-thunderbird-102.2.0-x86_64-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/102.2.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-36/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38472
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38473
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38476
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38477
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38478
(* Security fix *)
extra/sendmail/sendmail-8.17.1-x86_64-4.txz: Rebuilt.
In recent versions of glibc, USE_INET6 has been removed which caused sendmail
to reject mail from IPv6 addresses. Adding -DHAS_GETHOSTBYNNAME2=1 to the
site.config.m4 allows the reverse lookups to work again fixing this issue.
Thanks to talo.
extra/sendmail/sendmail-cf-8.17.1-noarch-4.txz: Rebuilt.
20220823192756 | Patrick J Volkerding | 2022-08-24 | 1 | -1/+1 |
* | Wed Sep 1 18:39:59 UTC 2021...a/util-linux-2.37.2-x86_64-2.txz: Rebuilt.
Rebuild with --disable-raw since the raw driver has been removed from the
kernel. Thanks to nobodino and SeB.
ap/vim-8.2.3394-x86_64-1.txz: Upgraded.
l/glib2-2.68.4-x86_64-2.txz: Rebuilt.
Better detect UTF-8 locales in libglib2.sh and libglib2.csh.
Thanks to Didier Spaier.
l/tidy-html5-5.8.0-x86_64-2.txz: Rebuilt.
Fixed manpage installation. Thanks to kaott.
n/iproute2-5.14.0-x86_64-1.txz: Upgraded.
x/libwacom-1.12-x86_64-1.txz: Upgraded.
x/wayland-protocols-1.22-noarch-1.txz: Upgraded.
xap/vim-gvim-8.2.3394-x86_64-1.txz: Upgraded.
extra/sendmail/sendmail-8.17.1-x86_64-2.txz: Rebuilt.
Rebuilt with -DUSE_EAI and -licui18n -licuuc -licudata added to
site.config.m4 to support SMTPUTF8. Thanks to niksoggia.
extra/sendmail/sendmail-cf-8.17.1-noarch-2.txz: Rebuilt.
20210901183959 | Patrick J Volkerding | 2021-09-02 | 1 | -2/+3 |
* | Thu Jul 23 20:08:16 UTC 2020...a/util-linux-2.36-x86_64-1.txz: Upgraded.
d/check-0.15.1-x86_64-1.txz: Upgraded.
d/parallel-20200722-noarch-1.txz: Upgraded.
x/mesa-20.1.4-x86_64-1.txz: Upgraded.
extra/sendmail/sendmail-8.16.1-x86_64-2.txz: Rebuilt.
Updated site.config.m4 and included -DDANE. Thanks to HQuest.
extra/sendmail/sendmail-cf-8.16.1-noarch-2.txz: Rebuilt.
testing/packages/gcc10/gcc-10.2.0-x86_64-1.txz: Upgraded.
testing/packages/gcc10/gcc-brig-10.2.0-x86_64-1.txz: Upgraded.
testing/packages/gcc10/gcc-g++-10.2.0-x86_64-1.txz: Upgraded.
testing/packages/gcc10/gcc-gdc-10.2.0-x86_64-1.txz: Upgraded.
testing/packages/gcc10/gcc-gfortran-10.2.0-x86_64-1.txz: Upgraded.
testing/packages/gcc10/gcc-gnat-10.2.0-x86_64-1.txz: Upgraded.
testing/packages/gcc10/gcc-go-10.2.0-x86_64-1.txz: Upgraded.
testing/packages/gcc10/gcc-objc-10.2.0-x86_64-1.txz: Upgraded.
20200723200816 | Patrick J Volkerding | 2020-07-24 | 1 | -5/+2 |
* | Mon May 28 19:12:29 UTC 2018...a/pkgtools-15.0-noarch-13.txz: Rebuilt.
installpkg: default line length for --terselength is the number of columns.
removepkg: added --terse mode.
upgradepkg: default line length for --terselength is the number of columns.
upgradepkg: accept -option in addition to --option.
ap/vim-8.1.0026-x86_64-1.txz: Upgraded.
d/bison-3.0.5-x86_64-1.txz: Upgraded.
e/emacs-26.1-x86_64-1.txz: Upgraded.
kde/kopete-4.14.3-x86_64-8.txz: Rebuilt.
Recompiled against libidn-1.35.
n/conntrack-tools-1.4.5-x86_64-1.txz: Upgraded.
n/libnetfilter_conntrack-1.0.7-x86_64-1.txz: Upgraded.
n/libnftnl-1.1.0-x86_64-1.txz: Upgraded.
n/links-2.16-x86_64-2.txz: Rebuilt.
Rebuilt to enable X driver for -g mode.
n/lynx-2.8.9dev.19-x86_64-1.txz: Upgraded.
n/nftables-0.8.5-x86_64-1.txz: Upgraded.
n/p11-kit-0.23.11-x86_64-1.txz: Upgraded.
n/ulogd-2.0.7-x86_64-1.txz: Upgraded.
n/whois-5.3.1-x86_64-1.txz: Upgraded.
xap/network-manager-applet-1.8.12-x86_64-1.txz: Upgraded.
xap/vim-gvim-8.1.0026-x86_64-1.txz: Upgraded.
20180528191229 | Patrick J Volkerding | 2018-05-31 | 1 | -0/+8 |