Update to 1.4.26.2; mitigates IAX2 denial of service AST-2009-006.

This makes an non-backwards-compatible change to the IAX2 protocol.
It can be disabled with various options, but is on by default.

IAX2 users, read http://downloads.digium.com/pub/security/AST-2009-006.html
and the new /usr/local/share/doc/asterisk/IAX2-security.pdf (available
online in http://svn.digium.com/svn/asterisk/tags/1.4.26.2/doc/).
This commit is contained in:
sthen 2009-09-04 00:46:35 +00:00
parent 12be6fa738
commit 7737a925e8
3 changed files with 15 additions and 14 deletions

View File

@ -1,12 +1,12 @@
# $OpenBSD: Makefile,v 1.59 2009/08/18 22:09:40 sthen Exp $
# $OpenBSD: Makefile,v 1.60 2009/09/04 00:46:35 sthen Exp $
SHARED_ONLY= Yes
COMMENT-main= open source multi-protocol PBX and telephony toolkit
VER= 1.4.26.1
VER= 1.4.26.2
# you can set PATCHVER=p0, p1 etc to bump everything,
# this takes care of the subpackage/flavor maze
PATCHVER= p0
PATCHVER=
CORESOUNDS= 1.4.15
DISTNAME= asterisk-${VER:S/rc/-rc/}
FULLPKGNAME-main= asterisk-${VER}${PATCHVER}

View File

@ -1,5 +1,5 @@
MD5 (asterisk-1.4.26.1.tar.gz) = m0b4Yo9D4dPCdUYM7uJmRg==
RMD160 (asterisk-1.4.26.1.tar.gz) = noojX0o2mDBJJCmsTTgwOS0rU9Q=
SHA1 (asterisk-1.4.26.1.tar.gz) = oq6LnAc7FLc0IznsO/n816VBTCg=
SHA256 (asterisk-1.4.26.1.tar.gz) = Q/appEIkjKoabxDGNLcGMvP9bWBpFulmlcTOuMJXVM4=
SIZE (asterisk-1.4.26.1.tar.gz) = 21068187
MD5 (asterisk-1.4.26.2.tar.gz) = WBgcKdmY+IP1Z9yXV6BBZw==
RMD160 (asterisk-1.4.26.2.tar.gz) = 5ygch1i8pr7hKWG096pls/9c9DM=
SHA1 (asterisk-1.4.26.2.tar.gz) = tXxmLiEW302WzjSQNub8KbaKDGk=
SHA256 (asterisk-1.4.26.2.tar.gz) = OE4IDjWa4oypMjgAo/oFhiEDQgObluy9ztnqKFUW7+k=
SIZE (asterisk-1.4.26.2.tar.gz) = 21436723

View File

@ -1,4 +1,4 @@
@comment $OpenBSD: PLIST-main,v 1.15 2009/08/18 22:09:40 sthen Exp $
@comment $OpenBSD: PLIST-main,v 1.16 2009/09/04 00:46:35 sthen Exp $
@conflict asterisk-sounds-<=1.2.1p2
@conflict app_conference-<=20070710
@newgroup _asterisk:545
@ -255,10 +255,10 @@ share/asterisk/keys/
share/asterisk/keys/freeworlddialup.pub
share/asterisk/keys/iaxtel.pub
share/asterisk/moh/
share/asterisk/moh/.asterisk-moh-opsound-wav
share/asterisk/moh/CHANGES-asterisk-moh-opsound-wav
share/asterisk/moh/CREDITS-asterisk-moh-opsound-wav
share/asterisk/moh/LICENSE-asterisk-moh-opsound-wav
share/asterisk/moh/.asterisk-moh-freeplay-wav
share/asterisk/moh/CHANGES-asterisk-moh-opsound-2.01
share/asterisk/moh/CREDITS-asterisk-moh-opsound-2.01
share/asterisk/moh/LICENSE-asterisk-moh-opsound-2.01
share/asterisk/moh/macroform-cold_day.wav
share/asterisk/moh/macroform-robot_dity.wav
share/asterisk/moh/macroform-the_simplicity.wav
@ -722,6 +722,7 @@ share/doc/asterisk/CODING-GUIDELINES
share/doc/asterisk/COPYING
share/doc/asterisk/CREDITS
share/doc/asterisk/ChangeLog
share/doc/asterisk/IAX2-security.pdf
share/doc/asterisk/LICENSE
share/doc/asterisk/PEERING
share/doc/asterisk/README
@ -770,7 +771,7 @@ share/doc/asterisk/misdn.txt
share/doc/asterisk/model.txt
share/doc/asterisk/modules.txt
share/doc/asterisk/mp3.txt
share/doc/asterisk/musiconhold-opsound.txt
share/doc/asterisk/musiconhold-fpm.txt
share/doc/asterisk/mysql.txt
share/doc/asterisk/osp.txt
share/doc/asterisk/privacy.txt