openbsd-ports/telephony
sthen 312710642c SECURITY update to Asterisk 1.8.12.2
AST-2012-007, AST-2012-008 fixed in the short-lived 1.8.12.1 release:

* A remotely exploitable crash vulnerability exists in the IAX2 channel
  driver if an established call is placed on hold without a suggested music
  class. Asterisk will attempt to use an invalid pointer to the music
  on hold class name, potentially causing a crash.

* A remotely exploitable crash vulnerability was found in the Skinny (SCCP)
  Channel driver. When an SCCP client closes its connection to the server,
  a pointer in a structure is set to NULL.  If the client was not in the
  on-hook state at the time the connection was closed, this pointer is later
  dereferenced. This allows remote authenticated connections the ability to
  cause a crash in the server, denying services to legitimate users.

Also from 1.8.12.2

* Resolve crash in subscribing for MWI notifications.

ASTOBJ_UNREF sets the variable to NULL after unreffing it, so the
variable should definitely not be used after that. To solve this in
the two cases that affect subscribing for MWI notifications, we
instead save the ref locally, and unref them in the error
conditions.
2012-05-30 22:45:26 +00:00
..
appkonference Mark as ONLY_FOR_ARCHS=i386/amd64, since it #errors out on others: 2012-04-05 21:15:29 +00:00
asterisk SECURITY update to Asterisk 1.8.12.2 2012-05-30 22:45:26 +00:00
asterisk-g729 Use RCDIR instead of /etc/rc.d when refering to packages rc scripts. 2012-04-22 11:41:55 +00:00
asterisk-native-sounds Switch to new-style REVISION/LIB_DEPENDS/WANTLIB 2010-07-27 09:27:23 +00:00
asterisk-openbsd-moh add 5.1 release song; ok ian@ 2012-03-15 20:25:33 +00:00
asterisk-sounds Switch to new-style REVISION/LIB_DEPENDS/WANTLIB 2010-07-27 09:27:23 +00:00
astmanproxy Garbage collect the /dev/arandom patches. 2012-03-08 12:13:00 +00:00
fobbit Remove surrounding quotes in COMMENT 2007-09-15 21:03:00 +00:00
gsutil new depends 2010-11-20 19:56:47 +00:00
iaxclient Make iaxclient work wiht newer ffmpeg API 2012-04-30 09:48:21 +00:00
iaxmodem new depends 2010-11-20 19:56:47 +00:00
kamailio Fixes to telephony/kamailio: 2012-05-09 21:27:47 +00:00
libosip2 Lawrence Teo takes maintainership 2012-01-18 13:45:25 +00:00
p5-asterisk update p5-asterisk to 1.01 and add example code (via MOD_CPAN_EXAMPLES) 2011-03-03 13:39:05 +00:00
p5-Net-SIP - update p5-Net-SIP to 0.64 2012-01-01 11:36:26 +00:00
pjsua Bugfix update to 1.14.2 2012-05-24 09:44:50 +00:00
siproxd Adjust sample siproxd config, from maintainer Lawrence Teo 2012-05-04 21:42:18 +00:00
spandsp update spandsp to 0.0.6pre18, from Brad 2011-03-10 09:36:42 +00:00
Makefile +asterisk-g729 2011-06-04 17:15:56 +00:00