Automatic conversion of the NetBSD pkgsrc CVS module, use with care
Find a file
jnemeth f975b24da7 Update to Asterisk 1.8.15.1. This fixes AST-2012-012 and AST-2012-013.
The Asterisk Development Team has announced security releases for Certified
Asterisk 1.8.11 and Asterisk 1.8 and 10. The available security releases are
released as versions 1.8.11-cert7, 1.8.15.1, 10.7.1, and 10.7.1-digiumphones.

The release of Asterisk 1.8.11-cert7, 1.8.15.1, 10.7.1, and 10.7.1-digiumphones
resolve the following two issues:

* A permission escalation vulnerability in Asterisk Manager Interface.  This
  would potentially allow remote authenticated users the ability to execute
  commands on the system shell with the privileges of the user running the
  Asterisk application.  Please note that the README-SERIOUSLY.bestpractices.txt
  file delivered with Asterisk has been updated due to this and other related
  vulnerabilities fixed in previous versions of Asterisk.

* When an IAX2 call is made using the credentials of a peer defined in a
  dynamic Asterisk Realtime Architecture (ARA) backend, the ACL rules for that
  peer are not applied to the call attempt. This allows for a remote attacker
  who is aware of a peer's credentials to bypass the ACL rules set for that
  peer.

These issues and their resolutions are described in the security advisories.

For more information about the details of these vulnerabilities, please read
security advisories AST-2012-012 and AST-2012-013, which were released at the
same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.15.1

The security advisories are available at:

 * http://downloads.asterisk.org/pub/security/AST-2012-012.pdf
 * http://downloads.asterisk.org/pub/security/AST-2012-013.pdf

Thank you for your continued support of Asterisk!
2012-09-09 06:04:01 +00:00
archivers Add missing conflict with statist-[0-9]* (bin/statist); ++pkgrevision 2012-09-08 22:46:44 +00:00
audio Add option "arts" disabled by default 2012-09-08 18:58:43 +00:00
benchmarks benchmarks/phoronix-test-suite: Change "cp -r" 2012-08-15 22:08:16 +00:00
biology Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
bootstrap Add support for --prefer-pkgsrc which will set PREFER_PKGSRC in the bootstrap 2012-07-26 13:00:48 +00:00
cad Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
chat Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
comms Update to Asterisk 1.8.15.1. This fixes AST-2012-012 and AST-2012-013. 2012-09-09 06:04:01 +00:00
converters Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
cross requires doxygen-1.8.2 2012-08-30 08:00:17 +00:00
databases Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
devel Update to 2.0.2 as requested in PR 46909, 2012-09-08 16:55:46 +00:00
distfiles
doc Updated archivers/freeze to 2.5nb3 2012-09-08 23:06:29 +00:00
editors Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
emulators Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
filesystems Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
finance Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
fonts Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
games Add missing CONFLICTS between exchess-book-small exchess-book-medium; ++pkgrevision 2012-09-08 23:05:03 +00:00
geography Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
graphics Restore PLIST.carbon=yes, lost during update. Should fix remaining 2012-09-09 01:28:06 +00:00
ham Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
inputmethod Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
lang Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
licenses rename osl-license to osl 2012-08-25 13:11:30 +00:00
mail Update to 4.34.0. From the changelog: 2012-09-08 19:39:21 +00:00
math Add missing conflict with freeze-[0-9]* (bin/statist); ++pkgrevision 2012-09-08 22:44:16 +00:00
mbone Recursive PKGREVISION bump for tcl and tk upgrade to 8.5.12 2012-08-21 23:49:18 +00:00
meta-pkgs Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
misc Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
mk Now MSGFMT_STRIP_MSGCTXT defaults to 'no', since devel/getttext-tools is the latest and can handle msgctxt tags 2012-09-03 14:59:33 +00:00
multimedia Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
net Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
news Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
packages
parallel Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
pkgtools DEPENDS on pkg_summary-utils>=0.58.4; ++pkgrevision 2012-09-08 18:20:04 +00:00
print Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
regress
security Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
shells Recursive PKGREVISION bump for tcl and tk upgrade to 8.5.12 2012-08-21 23:49:18 +00:00
sysutils Tell configure to not look for OpenSSL if not enabled via option. 2012-09-08 12:36:57 +00:00
templates
textproc Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
time Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
wm Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
www Revbump after updating graphics/cairo 2012-09-07 19:16:05 +00:00
x11 Update to 1.4. Notable changes: 2012-09-07 21:51:47 +00:00
Makefile
pkglocate Fix PR 39648: 2010-11-11 19:56:34 +00:00
README

$NetBSD: README,v 1.18 2005/05/07 22:18:28 wiz Exp $

Please see doc/pkgsrc.txt for information.