pkgsrc/comms/asterisk/distinfo
jnemeth f1928a0e2e Update to 1.2.37. This update is to fix two security issues.
1.2.36 fixed AST-2009-008, and 1.2.37 fixed AST-2009-010.  The
problem in AST-2009-008 is:

-----

It is possible to determine if a peer with a specific name is
configured in Asterisk by sending a specially crafted REGISTER
message twice. The username that is to be checked is put in the
user portion of the URI in the To header. A bogus non-matching
value is put into the username portion of the Digest in the
Authorization header. If the peer does exist the second REGISTER
will receive a response of "403 Authentication user name does not
match account name". If the peer does not exist the response will
be "404 Not Found" if alwaysauthreject is disabled and "401
Unauthorized" if alwaysauthreject is enabled.

-----

And, the problem in AST-2009-010 is:

-----

An attacker sending a valid RTP comfort noise payload containing
a data length of 24 bytes or greater can remotely crash Asterisk.

-----
2009-12-18 14:39:26 +00:00

18 lines
1,022 B
Text

$NetBSD: distinfo,v 1.45 2009/12/18 14:39:26 jnemeth Exp $
SHA1 (asterisk-1.2.37.tar.gz) = c9a3c4684e021f62b4d19f6e0c8fc11f64db19d6
RMD160 (asterisk-1.2.37.tar.gz) = 1de7ff96d3b1fd8d89f3ef7b3bb9e35bedccfb33
Size (asterisk-1.2.37.tar.gz) = 29899629 bytes
SHA1 (patch-aa) = 0070d874445d5bad7eb5a4cbd023a8f698e1f938
SHA1 (patch-ab) = 1bdae0ff206b63fe63373a307ecd23859c10cb79
SHA1 (patch-ac) = 4f783699c7d701030788646f8b961fa9245dc127
SHA1 (patch-ad) = 93a40eebdd2049cce2a976e54fcc3ea6a0548ebb
SHA1 (patch-ae) = a3b9dbf8017286dcc9327d65fb9c47c7b7ac5b79
SHA1 (patch-af) = 393bfbe218e843039fc9f4bc59a42ba1b9e896bd
SHA1 (patch-ag) = 7adec0d05371f6ffa56e067770c04c8acec2d922
SHA1 (patch-ai) = 81c0ff8f8a273562a64ab7cfb301d578e18808e3
SHA1 (patch-aj) = 3145d699119bb00efe049502c424ac7086ad1e18
SHA1 (patch-ak) = 3027134258138ca9163d9569548c7d4faffb874f
SHA1 (patch-al) = 1457c9a12eb5c5621eb244423c2190fb430866e7
SHA1 (patch-am) = a652b091462673390e19ab47e17500d055779094
SHA1 (patch-an) = 5bfb86853e868bc78eb0061871f4abce0df1ba2c