pkgsrc/comms
jnemeth 59c7e7c336 Update to Asterisk 10.12.4: this is a security fix update that fixes
AST-2013-006 and AST-2013-007.

The Asterisk Development Team has announced security releases for Certified
Asterisk 1.8.15, 11.2, and Asterisk 1.8, 10, and 11. The available security
releases are released as versions 1.8.15-cert4, 11.2-cert3, 1.8.24.1, 10.12.4,
10.12.4-digiumphones, and 11.6.1.

The release of these versions resolve the following issues:

* A buffer overflow when receiving odd length 16 bit messages in app_sms. An
  infinite loop could occur which would overwrite memory when a message is
  received into the unpacksms16() function and the length of the message is an
  odd number of bytes.

* Prevent permissions escalation in the Asterisk Manager Interface. Asterisk
  now marks certain individual dialplan functions as 'dangerous', which will
  inhibit their execution from external sources.

  A 'dangerous' function is one which results in a privilege escalation. For
  example, if one were to read the channel variable SHELL(rm -rf /) Bad
  Things(TM) could happen; even if the external source has only read
  permissions.

  Execution from external sources may be enabled by setting 'live_dangerously'
  to 'yes' in the [options] section of asterisk.conf. Although doing so is not
  recommended.

These issues and their resolutions are described in the security advisories.

For more information about the details of these vulnerabilities, please read
security advisories AST-2013-006 and AST-2013-007, which were
released at the same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.24.1

The security advisories are available at:

 * http://downloads.asterisk.org/pub/security/AST-2013-006.pdf
 * http://downloads.asterisk.org/pub/security/AST-2013-007.pdf

Thank you for your continued support of Asterisk!
2013-12-17 05:37:10 +00:00
..
asterisk Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
asterisk-sounds-de-x9media Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
asterisk-sounds-native Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
asterisk10 Update to Asterisk 10.12.4: this is a security fix update that fixes 2013-12-17 05:37:10 +00:00
asterisk18 Update to Asterisk 1.8.24.1: this is a security update that fixes 2013-12-17 02:29:11 +00:00
binkd format police 2011-04-07 13:18:23 +00:00
birda Fix undefined and broken loop. Fix obviously broken format string. 2013-10-10 00:02:17 +00:00
bthfp Fix printf argument type. Handle errors properly. Bump revision. 2013-09-10 14:13:40 +00:00
conserver Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
conserver8 PKGREVISION bumps for the security/openssl 1.0.1d update. 2013-02-06 23:20:50 +00:00
deforaos-phone PKGREVISION bump for json-c shlib rename. 2013-11-25 12:00:45 +00:00
dl-ezkit Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
efax Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
efax-gtk Recursive revbump from pango-1.36.0 2013-10-10 14:41:44 +00:00
estic remove obsolete patches (replaced by patch-estic-*.cc) 2012-12-13 09:08:39 +00:00
fidogate Use SPECIAL_PERMS and don't set USERGROUP_PHASE. PKGREVISION -> 7 2013-11-24 04:01:07 +00:00
gammu PKGREVISION bumps for the security/openssl 1.0.1d update. 2013-02-06 23:20:50 +00:00
gkermit Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
gnome-pilot Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
gsmlib Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
hylafax Requires jbigkit. Bump revision. 2013-08-30 16:57:35 +00:00
java-rxtx The printer port support is experimental, and only supported on some 2013-03-29 12:40:24 +00:00
jpilot Fix inline use. 2013-10-14 14:33:31 +00:00
jpilot-syncmal Recursive revbump from pango-1.36.0 2013-10-10 14:41:44 +00:00
kermit Depend on termcap as well as curses. 2013-10-10 16:58:03 +00:00
kyopon Continue on pointer sign warnings from clang. 2013-09-10 14:14:02 +00:00
libmal Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
libopensync Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
libopensync-plugin-evolution2 Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
libopensync-plugin-file Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
libopensync-plugin-kdepim Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
libopensync-plugin-syncml Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
libsyncml bump PKGREVISION for openobex update 2013-03-15 08:25:15 +00:00
libticables2 Import libticables2-1.3.3 as comms/libticables2. 2013-05-26 22:57:53 +00:00
libticalcs2 Import libticalcs2-1.1.7 as comms/libticalcs2. 2013-05-26 22:58:30 +00:00
libticonv Import libticonv-1.1.3 as comms/libticonv. 2013-05-26 22:59:06 +00:00
libtifiles2 Import libtifiles2-1.1.5 as comms/libtifiles2. 2013-05-26 22:59:42 +00:00
lirc Fix build failure on some Linuxes if CHECK_INTERPRETER=yes 2012-12-25 11:41:25 +00:00
lrzsz Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
malsync Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
mgetty+sendfax Bump PKGREVISION of all packages which create users, to pick up change of 2013-07-12 10:44:52 +00:00
minicom New for version 2.6.2: 2013-10-09 10:53:24 +00:00
modemd Forgotten patch to ensure presence of ioctl prototype. 2013-09-10 18:24:10 +00:00
msynctool Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
multisync-gui Revbump after updating textproc/icu 2013-10-19 09:06:55 +00:00
obexapp * .include "../../devel/readline/buildlink3.mk" with USE_GNU_READLINE=yes 2013-07-15 02:02:17 +00:00
obexftp CMAKE_INSTALL_MANDIR is specified by pkgsrc framework now. 2013-10-09 11:50:36 +00:00
op_panel Bump all packages for perl-5.18, that 2013-05-31 12:39:35 +00:00
openobex Add socket libraries on SunOS. Patch from Sebastian Wiedenroth. 2013-12-10 14:18:05 +00:00
p5-Asterisk Bump all packages for perl-5.18, that 2013-05-31 12:39:35 +00:00
p5-Data-AMF Bump all packages for perl-5.18, that 2013-05-31 12:39:35 +00:00
p5-Device-Gsm Bump all packages for perl-5.18, that 2013-05-31 12:39:35 +00:00
p5-Device-Modem Bump all packages for perl-5.18, that 2013-05-31 12:39:35 +00:00
p5-Device-SerialPort Bump all packages for perl-5.18, that 2013-05-31 12:39:35 +00:00
p5-Device-XBee-API Bump all packages for perl-5.18, that 2013-05-31 12:39:35 +00:00
p5-pilot-link bump for pilot-link-libs ncurses removal 2013-10-16 08:55:01 +00:00
p5-SMS-Send Fix/Update DEPENDS paterns for perl CORE modules, with some trivial fixes. 2013-12-09 14:17:41 +00:00
pilot-link bump for pilot-link-libs ncurses removal 2013-10-16 08:55:01 +00:00
pilot-link-libs Does not use curses or even termcap 2013-10-16 08:49:43 +00:00
pilotmgr Fix/Update DEPENDS paterns for perl CORE modules, with some trivial fixes. 2013-12-09 14:17:41 +00:00
plp Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
py-gammu Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
py-serial Add puyserial 26, which provides a uniform interface for accessing 2012-12-09 15:26:29 +00:00
qpage Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
ruby-termios Tweak GEM_CLEANBUILD for ruby200. 2013-07-21 02:38:24 +00:00
scmxx Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
snooper Fix attempt at detecting curses. 2013-11-05 17:38:41 +00:00
spandsp Remove fortran77 from USE_LANGUAGES as suggested by jnemeth@ 2013-06-09 23:29:34 +00:00
synce-librapi2 Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
synce-libsynce Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
synce-rra Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
synce-serial Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
tilp2 Recursive revbump from pango-1.36.0 2013-10-10 14:41:44 +00:00
tkhylafax Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
tn3270 tn3270 uses termcap as well as curses. 2013-10-10 16:31:28 +00:00
xisp Revbump after graphics/jpeg and textproc/icu 2013-01-26 21:36:13 +00:00
xtel Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days. 2012-10-03 11:24:38 +00:00
Makefile +libti* +tilp2; 2013-05-26 23:08:24 +00:00