Skip to content
Snippets Groups Projects
  1. Mar 16, 2018
  2. Feb 22, 2018
    • Timo Teräs's avatar
      main/asterisk: security upgrade to 15.2.2 · f0ae460f
      Timo Teräs authored
      AST-2018-001 (CVE-2018-7285): Crash when receiving unnegotiated dynamic payload
      AST-2018-002: Crash when given an invalid SDP media format description
      AST-2018-003: Crash with an invalid SDP fmtp attribute
      AST-2018-004 (CVE-2018-7284): Crash when receiving SUBSCRIBE request
      AST-2018-005 (CVE-2018-7286): Crash when large numbers of TCP connections are closed suddenly
      AST-2018-006 (CVE-2018-7287): WebSocket frames with 0 sized payload causes DoS
      f0ae460f
  3. Jan 15, 2018
  4. Jan 04, 2018
  5. Dec 30, 2017
    • Jakub Jirutka's avatar
      [various]: unify names of licenses according to SPDX · 63f5e7d2
      Jakub Jirutka authored
      This commit updates $license variable in all APKBUILDs to comply with
      short names specified by SPDX version 3.0 [1] where possible. It was
      done using find-and-replace method on substrings inside $license
      variables.
      
      Only license names were updated, not "expressions" specifying relation
      between the licenses (e.g. "X and Y", "X or Y", "X and (Y or Z)") or
      exceptions (e.g. "X with exceptions").
      
      Many licenses have a version or multiple variants, e.g. MPL-2.0,
      BSD-2-Clause, BSD-3-Clause. However, $license in many aports do not
      contain license version or variant. Since there's no way how to infer
      this information just from abuild, it were left without the variant
      suffix or version, i.e. non SPDX compliant.
      
      GNU licenses (AGPL, GFDL, GPL, LGPL) are especially complicated. They
      exist in two variants: -only (formerly e.g. GPL-2.0) and -or-later
      (formerly e.g. GPL-2.0+). We did not systematically noted distinguish
      between these variants, so GPL-2.0, GPL2, GPLv2 etc. may mean
      GPL-2.0-only or GPL-2.0-or-later. Thus GNU licenses without "+" (e.g.
      GPL2+) were left without the variant suffix, i.e. non SPDX compliant.
      
      Note: This commit just fixes format of the license names, no
      verification has been done if the specified license information is
      actually correct!
      
      [1]: https://spdx.org/licenses/
      63f5e7d2
  6. Dec 28, 2017
  7. Dec 19, 2017
  8. Dec 15, 2017
  9. Nov 13, 2017
  10. Nov 09, 2017
  11. Oct 31, 2017
  12. Sep 20, 2017
  13. Sep 01, 2017
  14. Aug 14, 2017
  15. Jul 12, 2017
  16. Jun 01, 2017
  17. May 22, 2017
  18. May 17, 2017
  19. Apr 18, 2017
  20. Apr 12, 2017
  21. Apr 05, 2017
  22. Mar 29, 2017
  23. Feb 15, 2017
  24. Jan 26, 2017
  25. Jan 12, 2017
  26. Dec 21, 2016
  27. Nov 23, 2016
  28. Nov 18, 2016
  29. Nov 11, 2016
  30. Nov 01, 2016
  31. Oct 26, 2016
  32. Oct 10, 2016
  33. Sep 09, 2016
    • Timo Teräs's avatar
      main/asterisk: upgrade to 13.11.1 · 372b48e0
      Timo Teräs authored
      AST-2016-006: Crash on ACK from unknown endpoint
      AST-2016-007: RTP Resource Exhaustion
      
      Remove our custom patch ASTERISK-19109 as unneeded since the
      administrative mute can be used for similar features. And remove
      musl-includes.patch as it was merged upstream.
      372b48e0
  34. Aug 13, 2016
  35. Jun 02, 2016
  36. Apr 25, 2016
Loading