sthen cf74a2af53 SECURITY update to Asterisk 11.14.1
* AST-2014-012: Fix error with mixed address family ACLs.

* AST-2014-014: Fix race condition where channels may get stuck in
ConfBridge under load.

* AST-2014-017 - app_confbridge: permission escalation/class authorization.

* AST-2014-018 - func_db: DB Dialplan function permission escalation via AMI.

...

2014-012 doesn't really affect OpenBSD; Asterisk generally only allows
a single bind address so can't really do multi AF on OpenBSD where
v4-mapped-in-v6 is disabled.

2014-017 is a priv escalation via AMI; ConfbridgeStartRecord didn't require
system privs, but allowed arbitrary system commands to be executed.
2014-11-21 12:40:49 +00:00
..
2014-10-12 00:36:33 +00:00
2013-03-11 11:35:43 +00:00
2013-03-11 11:35:43 +00:00
2014-04-27 20:52:50 +00:00
2013-11-09 23:19:01 +00:00
2014-04-24 23:49:26 +00:00
2014-10-22 13:00:54 +00:00
2013-10-06 19:12:08 +00:00
2014-09-25 19:32:56 +00:00