pkgsrc/comms
jnemeth 08b91504e4 Update to Asterisk 10.7.1. This fixes AST-2012-012 and AST-2012-013.
The Asterisk Development Team has announced security releases for Certified
Asterisk 1.8.11 and Asterisk 1.8 and 10. The available security releases are
released as versions 1.8.11-cert7, 1.8.15.1, 10.7.1, and 10.7.1-digiumphones.

The release of Asterisk 1.8.11-cert7, 1.8.15.1, 10.7.1, and 10.7.1-digiumphones
resolve the following two issues:

* A permission escalation vulnerability in Asterisk Manager Interface.  This
  would potentially allow remote authenticated users the ability to execute
  commands on the system shell with the privileges of the user running the
  Asterisk application.  Please note that the README-SERIOUSLY.bestpractices.txt
  file delivered with Asterisk has been updated due to this and other related
  vulnerabilities fixed in previous versions of Asterisk.

* When an IAX2 call is made using the credentials of a peer defined in a
  dynamic Asterisk Realtime Architecture (ARA) backend, the ACL rules for that
  peer are not applied to the call attempt. This allows for a remote attacker
  who is aware of a peer's credentials to bypass the ACL rules set for that
  peer.

These issues and their resolutions are described in the security advisories.

For more information about the details of these vulnerabilities, please read
security advisories AST-2012-012 and AST-2012-013, which were released at the
same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-10.7.1

The security advisories are available at:

 * http://downloads.asterisk.org/pub/security/AST-2012-012.pdf
 * http://downloads.asterisk.org/pub/security/AST-2012-013.pdf

Thank you for your continued support of Asterisk!
2012-09-09 06:09:16 +00:00
..
asterisk Add missing rpath in curl plugin. 2012-06-09 18:44:51 +00:00
asterisk-sounds-de-x9media
asterisk-sounds-extra add a conflict with asterisk >= 1.6.2 as that will include the extra sounds 2010-09-22 02:25:12 +00:00
asterisk-sounds-native
asterisk10 Update to Asterisk 10.7.1. This fixes AST-2012-012 and AST-2012-013. 2012-09-09 06:09:16 +00:00
asterisk16 comms/asterisk16: Mark NOT-FOR-DRAGONFLY 2012-07-15 16:26:11 +00:00
asterisk18 Update to Asterisk 1.8.15.1. This fixes AST-2012-012 and AST-2012-013. 2012-09-09 06:04:01 +00:00
binkd format police 2011-04-07 13:18:23 +00:00
birda Fix build on SunOS. 2012-02-16 16:40:34 +00:00
bthfp
conserver update master_sites. ftp service has been suspended. 2011-03-14 12:11:50 +00:00
conserver8 ftp.conserver.com re-directs to a machine that does not run an ftp 2010-12-06 10:59:10 +00:00
dl-ezkit Reset maintainer for retired developers. 2011-02-28 14:52:37 +00:00
efax Add -dMaxStripSize=0 to default ghostscript command line in efax.rc 2010-06-03 12:53:47 +00:00
efax-gtk Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
estic Fix build on SunOS. 2012-02-16 16:47:57 +00:00
fidogate Honor ${PKGINFODIR} in INSTALLATION_DIRS; should fix Linux build. 2012-06-18 01:51:41 +00:00
gammu Don't use strcharnul from the helper library, it doesn't end up as PIC 2012-07-09 19:17:51 +00:00
gkermit
gnome-pilot Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
gscmxx Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
gsmlib Fix build on SunOS. 2012-02-16 17:13:03 +00:00
hylafax Hack this to build against libtiff 4.x. With luck, it'll still work. 2012-04-08 03:25:03 +00:00
jpilot Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
jpilot-syncmal Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
kermit fix missing <time.h> inclusion that produces: 2012-05-17 20:29:13 +00:00
kyopon Reset maintainer for retired developers. 2011-02-28 14:52:37 +00:00
libmal update master_sites. 2010-01-31 21:34:39 +00:00
libopensync Recursive PKGREVISION bump for libxml2 buildlink addition. 2012-06-14 07:43:06 +00:00
libopensync-plugin-evolution2 Recursive PKGREVISION bump for libxml2 buildlink addition. 2012-06-14 07:43:06 +00:00
libopensync-plugin-file Recursive PKGREVISION bump for libxml2 buildlink addition. 2012-06-14 07:43:06 +00:00
libopensync-plugin-kdepim Recursive PKGREVISION bump for libxml2 buildlink addition. 2012-06-14 07:43:06 +00:00
libopensync-plugin-syncml Recursive PKGREVISION bump for libxml2 buildlink addition. 2012-06-14 07:43:06 +00:00
libsyncml Recursive PKGREVISION bump for libxml2 buildlink addition. 2012-06-14 07:43:06 +00:00
lrzsz recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
malsync Fix build on SunOS. 2012-02-16 17:25:16 +00:00
mgetty+sendfax Use SPECIAL_PERMS and switch to user-destdir mode. While this is intended 2012-04-08 01:28:35 +00:00
minicom Add missing mk/termcap buildlink. 2011-12-17 10:14:56 +00:00
modemd Reset maintainer, developer has left the building 2012-04-15 22:00:58 +00:00
msynctool Recursive PKGREVISION bump for libxml2 buildlink addition. 2012-06-14 07:43:06 +00:00
multisync-gui Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
obexapp since in recent NetBSD, the /etc/rc.d/sdpd script was merged into 2012-06-16 19:28:19 +00:00
obexftp Fix build on SunOS. 2012-02-16 17:35:30 +00:00
op_panel
openobex
p5-Asterisk Updated to 1.03 2012-04-01 18:49:01 +00:00
p5-Device-Gsm Updated to 1.60 2012-04-01 18:56:54 +00:00
p5-Device-Modem Updated to 1.56 2012-04-01 19:00:49 +00:00
p5-Device-SerialPort Add LICENSE. 2011-11-05 23:13:27 +00:00
p5-Device-XBee-API Update to Device-XBee-API version 0.4 2011-09-01 02:29:38 +00:00
p5-pilot-link Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
p5-SMS-Send Updated to 1.06 2012-04-01 19:04:34 +00:00
pilot-link Fix build on SunOS. 2012-02-16 17:35:30 +00:00
pilot-link-libs
pilotmgr
plp Fix build on SunOS. 2012-02-16 17:35:30 +00:00
py-gammu All supported python versions in pkgsrc support eggs, so remove 2012-04-08 20:21:41 +00:00
qpage DESTDIR support 2010-01-29 16:38:20 +00:00
ruby-termios * Remove .require_paths from PLIST 2011-11-08 15:37:33 +00:00
scmxx Fix build on SunOS. 2012-02-16 17:47:04 +00:00
snooper Fix build on SunOS. 2012-02-16 17:47:04 +00:00
spandsp Set BUILDLINK_ABI_DEPENDS correctly (with +=, not ?=) 2012-05-07 01:53:12 +00:00
synce-librapi2
synce-libsynce Fix build on SunOS. 2012-02-16 17:47:04 +00:00
synce-rra Fix build on SunOS. 2012-02-16 17:47:04 +00:00
synce-serial
tkhylafax DESTDIR support 2010-01-29 16:38:20 +00:00
tn3270 USE_TOOLS, not TOOLS. Apparently my fault 2012-01-04 14:33:53 +00:00
xisp Fix build on SunOS. 2012-02-17 13:49:47 +00:00
xtel Drop dependency on libXp (from Imake) 2012-05-03 09:55:29 +00:00
Makefile add and enable asterisk10 2012-01-15 18:39:32 +00:00