pkgsrc/comms
jnemeth 38c2539a3f Update to Asterisk 1.6.2.24. This fixes AST-2012-004 and AST-2012-005.
The 1.6.2 series went End of Life on April 21st 2012, so this was
the last update.  This package will be deleted in the not too
distnat future.

The Asterisk Development Team has announced security releases for
Asterisk 1.6.2 , 1.8, and 10. The available security releases are
released as versions 1.6.2.24, 1.8.11.1, and 10.3.1.

The release of Asterisk 1.6.2.24, 1.8.11.1, and 10.3.1 resolve the
following two issues:

 * A permission escalation vulnerability in Asterisk Manager
   Interface.  This would potentially allow remote authenticated
   users the ability to execute commands on the system shell with
   the privileges of the user running the Asterisk application.

 * A heap overflow vulnerability in the Skinny Channel driver.
   The keypad button message event failed to check the length of
   a fixed length buffer before appending a received digit to the
   end of that buffer.  A remote authenticated user could send
   sufficient keypad button message events that th e buffer would
   be overrun.

These issues and their resolution are described in the security
advisories.

For more information about the details of these vulnerabilities,
please read security advisories AST-2012-004, AST-2012-005, and
AST-2012-006, which were released at the same time as this
announcement.

For a full list of changes in the current releases, please see the
ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.6.2.24

The security advisories are available at:

 * http://downloads.asterisk.org/pub/security/AST-2012-004.pdf
 * http://downloads.asterisk.org/pub/security/AST-2012-005.pdf

Thank you for your continued support of Asterisk!
2012-04-30 03:19:40 +00:00
..
asterisk Fix build on SunOS. 2012-02-16 16:13:51 +00:00
asterisk-sounds-de-x9media Change default for zip extraction to leave files as they are. 2009-08-25 11:56:34 +00:00
asterisk-sounds-extra add a conflict with asterisk >= 1.6.2 as that will include the extra sounds 2010-09-22 02:25:12 +00:00
asterisk-sounds-native
asterisk10 Update to Asterisk 10.3.1. This Fixes AST-2012-004, AST-2012-005, 2012-04-30 02:53:25 +00:00
asterisk16 Update to Asterisk 1.6.2.24. This fixes AST-2012-004 and AST-2012-005. 2012-04-30 03:19:40 +00:00
asterisk18 Update to Asterisk 1.8.11.1. This fixes AST-2012-004, AST-2012-005, 2012-04-30 02:33:21 +00:00
binkd format police 2011-04-07 13:18:23 +00:00
birda Fix build on SunOS. 2012-02-16 16:40:34 +00:00
bthfp Use standard location for LICENSE line (in MAINTAINER/HOMEPAGE/COMMENT 2009-05-19 08:59:00 +00:00
conserver update master_sites. ftp service has been suspended. 2011-03-14 12:11:50 +00:00
conserver8 ftp.conserver.com re-directs to a machine that does not run an ftp 2010-12-06 10:59:10 +00:00
dl-ezkit Reset maintainer for retired developers. 2011-02-28 14:52:37 +00:00
efax Add -dMaxStripSize=0 to default ghostscript command line in efax.rc 2010-06-03 12:53:47 +00:00
efax-gtk Recursive bump for pcre-8.30* (shlib major change) 2012-03-03 00:11:51 +00:00
estic Fix build on SunOS. 2012-02-16 16:47:57 +00:00
fidogate Set perl path from TOOLS_PATH.perl instead of assuming it is in PREFIX. 2012-02-28 11:21:50 +00:00
gammu Fix build on SunOS. 2012-02-16 17:13:03 +00:00
gkermit Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
gnome-pilot Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
gscmxx Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
gsmlib Fix build on SunOS. 2012-02-16 17:13:03 +00:00
hylafax Hack this to build against libtiff 4.x. With luck, it'll still work. 2012-04-08 03:25:03 +00:00
jpilot Recursive bump for pcre-8.30* (shlib major change) 2012-03-03 00:11:51 +00:00
jpilot-syncmal Recursive bump for pcre-8.30* (shlib major change) 2012-03-03 00:11:51 +00:00
kermit 1) Add missing mk/curses buildlink. 2011-12-06 01:19:15 +00:00
kyopon Reset maintainer for retired developers. 2011-02-28 14:52:37 +00:00
libmal update master_sites. 2010-01-31 21:34:39 +00:00
libopensync Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
libopensync-plugin-evolution2 Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
libopensync-plugin-file Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
libopensync-plugin-kdepim Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
libopensync-plugin-syncml Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
libsyncml Recursive bump for pcre-8.30* (shlib major change) 2012-03-03 00:11:51 +00:00
lrzsz recursive bump from gettext-lib shlib bump. 2011-04-22 13:41:54 +00:00
malsync Fix build on SunOS. 2012-02-16 17:25:16 +00:00
mgetty+sendfax Use SPECIAL_PERMS and switch to user-destdir mode. While this is intended 2012-04-08 01:28:35 +00:00
minicom Add missing mk/termcap buildlink. 2011-12-17 10:14:56 +00:00
modemd Reset maintainer, developer has left the building 2012-04-15 22:00:58 +00:00
msynctool Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
multisync-gui Recursive bump from icu shlib major bumped to 49. 2012-04-27 12:31:32 +00:00
obexapp update to 1.4.15 2011-07-13 20:51:41 +00:00
obexftp Fix build on SunOS. 2012-02-16 17:35:30 +00:00
op_panel Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
openobex MASTER_SITES=http://www.kernel.org/pub/linux/bluetooth/ 2009-08-09 08:00:46 +00:00
p5-Asterisk Updated to 1.03 2012-04-01 18:49:01 +00:00
p5-Device-Gsm Updated to 1.60 2012-04-01 18:56:54 +00:00
p5-Device-Modem Updated to 1.56 2012-04-01 19:00:49 +00:00
p5-Device-SerialPort Add LICENSE. 2011-11-05 23:13:27 +00:00
p5-Device-XBee-API Update to Device-XBee-API version 0.4 2011-09-01 02:29:38 +00:00
p5-pilot-link Revision bump after updating perl5 to 5.14.1. 2011-08-14 07:38:55 +00:00
p5-SMS-Send Updated to 1.06 2012-04-01 19:04:34 +00:00
pilot-link Fix build on SunOS. 2012-02-16 17:35:30 +00:00
pilot-link-libs Update to 0.12.4: 2009-08-09 08:36:34 +00:00
pilotmgr Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
plp Fix build on SunOS. 2012-02-16 17:35:30 +00:00
py-gammu All supported python versions in pkgsrc support eggs, so remove 2012-04-08 20:21:41 +00:00
qpage DESTDIR support 2010-01-29 16:38:20 +00:00
ruby-termios * Remove .require_paths from PLIST 2011-11-08 15:37:33 +00:00
scmxx Fix build on SunOS. 2012-02-16 17:47:04 +00:00
snooper Fix build on SunOS. 2012-02-16 17:47:04 +00:00
spandsp Revbump for 2012-02-06 12:39:42 +00:00
synce-librapi2 Simply and speed up buildlink3.mk files and processing. 2009-03-20 19:23:50 +00:00
synce-libsynce Fix build on SunOS. 2012-02-16 17:47:04 +00:00
synce-rra Fix build on SunOS. 2012-02-16 17:47:04 +00:00
synce-serial Remove @dirrm entries from PLISTs 2009-06-14 17:38:38 +00:00
tkhylafax DESTDIR support 2010-01-29 16:38:20 +00:00
tn3270 USE_TOOLS, not TOOLS. Apparently my fault 2012-01-04 14:33:53 +00:00
xisp Fix build on SunOS. 2012-02-17 13:49:47 +00:00
xtel Fix build on SunOS. 2012-02-16 18:00:20 +00:00
Makefile add and enable asterisk10 2012-01-15 18:39:32 +00:00