pkgsrc/comms
jnemeth 636c6f0efe Update to 1.8.7.1 -- this update fixes AST-2011-012
pkgsrc change:  now what sqlite3 has been imported into NetBSD, enable it

               Asterisk Project Security Advisory - AST-2011-012

          Product         Asterisk
          Summary         Remote crash vulnerability in SIP channel driver
     Nature of Advisory   Remote crash
       Susceptibility     Remote authenticated sessions
          Severity        Critical
       Exploits Known     No
        Reported On       October 4, 2011
        Reported By       Ehsan Foroughi
         Posted On        October 17, 2011
      Last Updated On     October 17, 2011
      Advisory Contact    Terry Wilson <twilson@digium.com>
          CVE Name        CVE-2011-4063

    Description  A remote authenticated user can cause a crash with a
                 malformed request due to an unitialized variable.

    Resolution  Ensure variables are initialized in all cases when parsing
                the request.

                               Affected Versions
           Product         Release Series
    Asterisk Open Source       1.8.x       All versions
    Asterisk Open Source        10.x       All versions (currently in beta)

                                  Corrected In
                  Product                              Release
            Asterisk Open Source                 1.8.7.1, 10.0.0-rc1

                                    Patches
                             Download URL                           Revision
   http://downloads.asterisk.org/pub/security/AST-2011-012-1.8.diff 1.8
   http://downloads.asterisk.org/pub/security/AST-2011-012-10.diff  10

            Links

    Asterisk Project Security Advisories are posted at
    http://www.asterisk.org/security

    This document may be superseded by later versions; if so, the latest
    version will be posted at
    http://downloads.digium.com/pub/security/AST-2011-012.pdf and
    http://downloads.digium.com/pub/security/AST-2011-012.html

                                Revision History
           Date                 Editor                 Revisions Made

               Asterisk Project Security Advisory - AST-2011-012
              Copyright (c) 2011 Digium, Inc. All Rights Reserved.
  Permission is hereby granted to distribute and publish this advisory in its
                           original, unaltered form.
2011-10-17 23:40:50 +00:00
..
asterisk Remove zaptel option, zaptel-netbsd was removed. 2011-10-06 08:35:01 +00:00
asterisk-sounds-de-x9media Change default for zip extraction to leave files as they are. 2009-08-25 11:56:34 +00:00
asterisk-sounds-extra add a conflict with asterisk >= 1.6.2 as that will include the extra sounds 2010-09-22 02:25:12 +00:00
asterisk-sounds-native Fix installation due to missing directories and add DESTDIR support. 2007-06-29 22:54:06 +00:00
asterisk16 Revert previous. This package was marked OWNER= for a reason! 2011-10-11 03:15:50 +00:00
asterisk18 Update to 1.8.7.1 -- this update fixes AST-2011-012 2011-10-17 23:40:50 +00:00
binkd format police 2011-04-07 13:18:23 +00:00
birda Add missing include 2011-09-25 19:40:28 +00:00
bthfp Use standard location for LICENSE line (in MAINTAINER/HOMEPAGE/COMMENT 2009-05-19 08:59:00 +00:00
conserver update master_sites. ftp service has been suspended. 2011-03-14 12:11:50 +00:00
conserver8 ftp.conserver.com re-directs to a machine that does not run an ftp 2010-12-06 10:59:10 +00:00
dl-ezkit Reset maintainer for retired developers. 2011-02-28 14:52:37 +00:00
efax Add -dMaxStripSize=0 to default ghostscript command line in efax.rc 2010-06-03 12:53:47 +00:00
efax-gtk recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
estic Bump revision. 2011-03-31 17:55:25 +00:00
fidogate Needs group early during installation 2010-06-19 12:18:51 +00:00
gammu recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
gkermit Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
gnome-pilot recursive bump from gnome-vfs drop crypto dependency. 2011-07-21 13:05:46 +00:00
gscmxx Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
gsmlib recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
hylafax Let to use new C++ style headers first for CXX runtime check, 2011-09-03 08:52:59 +00:00
jpilot recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
jpilot-syncmal recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
kermit Update to 9.0.302, see http://www.columbia.edu/kermit/ck90.html for more 2011-08-25 14:54:06 +00:00
kyopon Reset maintainer for retired developers. 2011-02-28 14:52:37 +00:00
libmal update master_sites. 2010-01-31 21:34:39 +00:00
libopensync Fix a bunch of real world bugs that clang warns about. Fix up fix for 2011-07-21 15:35:55 +00:00
libopensync-plugin-evolution2 recursive bump from textproc/icu shlib major bump. 2011-06-10 09:39:41 +00:00
libopensync-plugin-file recursive bump from textproc/icu shlib major bump. 2011-06-10 09:39:41 +00:00
libopensync-plugin-kdepim recursive bump from textproc/icu shlib major bump. 2011-06-10 09:39:41 +00:00
libopensync-plugin-syncml recursive bump from textproc/icu shlib major bump. 2011-06-10 09:39:41 +00:00
libsyncml recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
lrzsz recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
malsync Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
mgetty+sendfax Uses chown during install phase, so ensure that the user/group exists 2011-09-24 19:30:40 +00:00
minicom Changes 2.5: 2011-08-01 09:30:33 +00:00
modemd Add a missing includes 2011-09-25 19:41:11 +00:00
msynctool recursive bump from textproc/icu shlib major bump. 2011-06-10 09:39:41 +00:00
multisync-gui recursive bump from textproc/icu shlib major bump. 2011-06-10 09:39:41 +00:00
obexapp update to 1.4.15 2011-07-13 20:51:41 +00:00
obexftp Bluetooth support for DragonFly. Bump PKGREVISION. PR pkg/41640. 2009-07-20 05:56:02 +00:00
op_panel Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
openobex MASTER_SITES=http://www.kernel.org/pub/linux/bluetooth/ 2009-08-09 08:00:46 +00:00
p5-Asterisk Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
p5-Device-Gsm Update to 1.58: 2011-08-16 19:58:06 +00:00
p5-Device-Modem Update to 1.54: 2011-08-16 19:56:56 +00:00
p5-Device-SerialPort Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
p5-Device-XBee-API Update to Device-XBee-API version 0.4 2011-09-01 02:29:38 +00:00
p5-pilot-link Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
p5-SMS-Send Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
pilot-link Fix build with perl 5.14.1 2011-10-14 11:26:31 +00:00
pilot-link-libs Update to 0.12.4: 2009-08-09 08:36:34 +00:00
pilotmgr Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
plp Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
py-gammu Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
qpage DESTDIR support 2010-01-29 16:38:20 +00:00
ruby-termios Bump PKGREVISION due to ABI change of ruby18-base. 2011-02-21 16:01:10 +00:00
scmxx recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
snooper PKG_DESTDIR_SUPPORT 2009-12-17 21:43:16 +00:00
spandsp Add a patch for PR/44766. The issue was that older versions of gas 2011-09-01 09:22:30 +00:00
synce-librapi2 Simply and speed up buildlink3.mk files and processing. 2009-03-20 19:23:50 +00:00
synce-libsynce Simply and speed up buildlink3.mk files and processing. 2009-03-20 19:23:50 +00:00
synce-rra Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
synce-serial Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
tkhylafax DESTDIR support 2010-01-29 16:38:20 +00:00
tn3270 Add a workaround for DragonFly arpa/telnet.h. 2010-12-30 09:22:43 +00:00
xisp remove dead mirror. 2010-04-17 15:48:22 +00:00
xtel Fix native X build by cleaning up FONTDIR after imake. Ride previous bump. 2011-10-09 03:53:31 +00:00
Makefile Remove packages depending on the removed packages. 2011-10-02 14:32:31 +00:00