Commit Graph

16 Commits

Author SHA1 Message Date
ian
fab7c3a824 Upgrade to 1.2.22 to fix several remote exploits, from Stuart, tested by me 2007-07-19 01:31:27 +00:00
jolan
994a77a545 SECURITY: update to 1.2.19, from maintainer stuart henderson
ASA-2007-013: chan_iax2.c assumes strings are null-terminated without
validating them, potential buffer overrun/information disclosure
2007-07-02 14:03:34 +00:00
jolan
e137319740 SECURITY: update to 1.2.18 from maintainer stuart henderson
ASA-2007-011: Multiple problems in SIP channel parser handling response
codes
ASA-2007-012: Remote Crash Vulnerability in Manager Interface
2007-05-02 17:29:25 +00:00
espie
d4ebcd974d more base64 checksums 2007-04-05 17:26:05 +00:00
jolan
b55e239460 SECURITY: update to 1.2.17, fixes a(nother) remote DoS in chan_sip:
http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html

from maintainer stuart henderson
2007-03-21 15:51:54 +00:00
jolan
7d42dc4e37 SECURITY: update to 1.2.16 which fixes a remote DoS in chan_sip
from maintainer stuart henderson
2007-03-15 10:56:31 +00:00
ian
039ed98d9e 1.2.14->1.2.15 from maintainer, tested on i386 & amd64. 2007-02-11 01:03:28 +00:00
jolan
82ddf3f4d8 update to 1.2.14, from stuart henderson 2006-12-22 22:16:10 +00:00
jolan
73cc4fa6d9 SECURITY: update to 1.2.13 which fixes a vulnerability in the
chan_skinny module.  for more details see:

http://www.asterisk.org/node/109

from maintainer
2006-10-19 21:19:07 +00:00
jolan
53cc38430a - update to 1.2.12.1
- be careful not to pick up odbc/popt if they happened to be installed

from maintainer stuart henderson
2006-09-24 21:09:25 +00:00
naddy
ca6257ce12 SECURITY:
Update to 1.2.9.1 which addresses a security vulnerability in the IAX2
channel driver (chan_iax2). The vulnerability affects all users with
IAX2 clients that might be compromised or used by a malicious user, and
can lead to denial of service attacks and random Asterisk server crashes
via a relatively trivial exploit.

From: maintainer Stuart Henderson <stu@spacehopper.org>
2006-06-12 19:04:10 +00:00
todd
43939e07ca Work by and tested by ian@ and Stuart Henderson, comments by jolan@ 2006-02-02 03:41:36 +00:00
jolan
c7aee7ccf1 update to 1.0.9, ok jcs pval
most notably fixes an overflow in the management interface (which is not
enabled by default)
2005-08-15 17:36:06 +00:00
jcs
21340eeda8 update to asterisk-1.0.7
- put jolan's mirror second
- RUN_DEPENDS on sox and mpg123 for music on hold
- install example indications.conf so ringing works

ok jolan@
2005-05-01 02:12:46 +00:00
naddy
ae76d3ea1f SIZE 2005-01-05 17:21:50 +00:00
jolan
ea994b03de asterisk-1.0.0, open source pbx 2004-09-26 00:38:23 +00:00