commits
(cherry picked from commit ad1e2500efd0aa49b0dc7427bf69d4879f3b0ff5)
(cherry picked from commit aec730a0af4c977513ce28236cbecaca72af6901)
Kyndig on IRC noticed that building `ninja` from source would fail due
to a patch 404'ing (because the repo appears to no longer exist). Fetch
from upstream instead.
(cherry picked from commit 91d4e9aa97ab19a1364159a7617336aeb6a864f8)
cc #85742
Changelog: https://www.ruby-lang.org/en/news/2020/03/31/ruby-2-6-6-released/
(cherry picked from commit b312ecf34e110d2d1fda3601c7b5a5a46a41dbfd)
Changelog: https://www.ruby-lang.org/en/news/2020/03/31/ruby-2-5-8-released/
(cherry picked from commit 99b09d6b8f201379bb34f01a1acacdc1c3950c46)
Fixes: #78702
Closes: #79260
(cherry picked from commit 157f392f57ddcb3a0c8b7062dc01469c6b43fdce)
(cherry picked from commit 5c39e8c8adba37e6f18d067d678e879062c6ea49)
cc #78479
(cherry picked from commit e279676f480c0bce3ea9baea90cf926f07071de1)
This reverts commit 93aabab7605c21f5962df2dffa7fee9ac17ba848.
This reverts commit e9156086187b09970e5cdb5178450c73ae59ecd6.
Based on change in master at d1bd0fbfcc0ee6b0fcaf662cca5ee4ba8932f141
opened in https://github.com/NixOS/nixpkgs/pull/77442
Fixes #77266: CVE-2019-1551
https://www.openssl.org/news/secadv/20191206.txt
(cherry picked from commit 961d0cf9f5f5e762eacb1ceda10d45cd35a81662)
(cherry picked from commit 3f0fee752d6f5f5d0774cc7d9bcf8491562b453b)
The wrapper need a writable directory to work, so remove the symlink
to a read-only one if it occurs.
(cherry picked from commit c13f1a508d6128d7cdea247d21015b5df8e44132)
We were previously just installing the "out" output which broke when
we recently changed to generating multiple outputs.
Fixes #76837
Fixes #75964 and #68560 (many CVEs).
https://git.ffmpeg.org/gitweb/ffmpeg.git/blob/289a79d545e83a:/Changelog
(cherry picked from commit 37e1da287483eac4a62597c73f31708389bfad19)
[r19.03] dpdk: 17.11.2 -> 17.11.9, addressing CVE-2019-14818
CVE-2019-1348, CVE-2019-1349, CVE-2019-1350, CVE-2019-1351,
CVE-2019-1352, CVE-2019-1353, CVE-2019-1354, CVE-2019-1387
Link: https://lore.kernel.org/git/xmqqr21cqcn9.fsf@gitster-ct.c.googlers.com/
[19.03] djvulibre: patching multiple CVEs
Addresses:
https://github.com/NixOS/nixpkgs/issues/73624
https://github.com/NixOS/nixpkgs/issues/70086
(cherry picked from commit be7e51a083f3cc5560b3683d915248c32b317acc)
(#74514)
Vuln roundup #73664 -- r19.03 channel
Version bump from 0.9.11 to 0.9.12 fixes:
* CVE-2018-6307
* CVE-2018-15126
* CVE-2018-15127
* CVE-2018-20019
* CVE-2018-20020
* CVE-2018-20021
* CVE-2018-20022
* CVE-2018-20023
* CVE-2018-20024
* CVE-2018-20748
* CVE-2018-20749
Plus add two upstream patches to fix:
* CVE-2018-20750
* CVE-2019-15681
(cherry picked from commit 3fb4e09812bb17d0d33087dc7c3255eccec2e5fb)
(adjusted cherry-pick from 55b583d334005cc0e51226f7b73f33ee2aed3938)
Security fixes for:
* CVE-2019-8287
* CVE-2019-15678
* CVE-2019-15679
* CVE-2019-15680
mostly adapted from patches fixing similar issues in the actively
maintained libvnc
(#73970)
(cherry picked from commit 2482f8b8dca0f57466d20f9dcf2ff3d5cd16adbf)
(cherry picked from commit b8920d3dba0e594ab6a8e37fb227af9462fa0590)
Backport of #73882
addresses CVE-2019-18849
(cherry picked from commit b9d458d91c1d39b8b5954c84afc862b044cf84d5)
[r19.03] slurm: add patch addressing CVE-2019-12838
including a prerequisite patch to allow the actual fix to apply cleanly
(#73792)
(cherry picked from commit 593def2396e2a88dbf9a26dcc892772b39c773a7)
[19.03] samba: add patches for CVE-2019-3880, CVE-2019-10218, CVE-2019-14833 & CVE-2019-14847
Fixes #71201
(cherry picked from commit ff066a107bbaf17808462d7d986ff43234c66535)
CVE-2018-1000022 in electrum
(cherry picked from commit a50507a6cce1bf49a667de23fb7d3355eedb8f3d)
(cherry picked from commit 908f6240d89293dbcdc41758ac0b6f2c1a7107e8)
Fixes #57153.
(cherry picked from commit 8c997725a288f140703b3fbb836e70acf58557e3)
using patches from the 4.8 & 4.9 branches, but luckily these all apply and
work against 4.7
Extracted from https://github.com/NixOS/nixpkgs/pull/70216.
(cherry picked from commit 96a1dbac972c4f67aea7ee548f4e5531003f8ab0)
(cherry picked from commit c115659884612bce7d98ca57948e1258cb4370b6)
cc #72804
(#73115)
(cherry picked from commit 7dacaa056c4a1054759ae813eb9f91b0633601de)
(cherry picked from commit 03d6145cb020aa4c782c78580d2d049b42ea5a28)
(cherry picked from commit 5270c3a03ee5657551f16b31da057dda81c8b0f9)
/cc #57158.
[r19.03] varnish6: add patch for CVE-2019-15892
[r19.03] qemu: add patches for CVE-2019-13164 & CVE-2019-14378
[r19.03] opencv3: 3.4.5 -> 3.4.8, addressing CVE-2019-14491, CVE-2019-14492 & CVE-2019-15939
(cherry picked from commit 38a4dc2a4db7cd292b8871e18ee67a22fcd2b3ae & adapted)
Fixes #71075. I'm really tired of these, so lemme try this approach.
(cherry picked from commit d628521d0b79df8882980a897f1e91fe78c29660)
addressing CVE-2019-14491, CVE-2019-14492 & CVE-2019-15939
all internal downloads are unchanged for this release
(cherry picked from commit a38ee9f002a36c323b5facd19dcecf65274562c0 & adapted)
(cherry picked from commit e834edcbddaabe967f51abd4fe1fea0ba1e569ab)
[r19.03] pythonPackages.koji: 1.13.0 -> 1.14.3 (security)
[r19.03] file: add patch for CVE-2019-18218
as with master, not all of the CVE-2019-14817 patch applies cleanly, but
the parts that do should provide some protection
(cherry picked from commit bd3f644a9067e3c70e296cca8a4cdbb8b6bbc2f5)
(cherry picked from commit f55969bbb365f63d4608876a4dc3522712d4c737)
(cherry picked from commit ad1e2500efd0aa49b0dc7427bf69d4879f3b0ff5)
(cherry picked from commit aec730a0af4c977513ce28236cbecaca72af6901)
(cherry picked from commit e279676f480c0bce3ea9baea90cf926f07071de1)
(#74514)
Vuln roundup #73664 -- r19.03 channel
Version bump from 0.9.11 to 0.9.12 fixes:
* CVE-2018-6307
* CVE-2018-15126
* CVE-2018-15127
* CVE-2018-20019
* CVE-2018-20020
* CVE-2018-20021
* CVE-2018-20022
* CVE-2018-20023
* CVE-2018-20024
* CVE-2018-20748
* CVE-2018-20749
Plus add two upstream patches to fix:
* CVE-2018-20750
* CVE-2019-15681
(cherry picked from commit 3fb4e09812bb17d0d33087dc7c3255eccec2e5fb)