summaryrefslogtreecommitdiff
path: root/comms/asterisk
AgeCommit message (Collapse)AuthorFilesLines
2011-10-06Remove zaptel option, zaptel-netbsd was removed.wiz2-19/+4
2011-08-07Bump PKGREVISION for perl update.jnemeth1-2/+2
2011-04-22recursive bump from gettext-lib shlib bump.obache1-2/+2
2010-01-17Recursive PKGREVISION bump for jpeg update to 8.wiz1-1/+2
2009-12-18 Update to 1.2.37. This update is to fix two security issues.jnemeth2-6/+6
1.2.36 fixed AST-2009-008, and 1.2.37 fixed AST-2009-010. The problem in AST-2009-008 is: ----- It is possible to determine if a peer with a specific name is configured in Asterisk by sending a specially crafted REGISTER message twice. The username that is to be checked is put in the user portion of the URI in the To header. A bogus non-matching value is put into the username portion of the Digest in the Authorization header. If the peer does exist the second REGISTER will receive a response of "403 Authentication user name does not match account name". If the peer does not exist the response will be "404 Not Found" if alwaysauthreject is disabled and "401 Unauthorized" if alwaysauthreject is enabled. ----- And, the problem in AST-2009-010 is: ----- An attacker sending a valid RTP comfort noise payload containing a data length of 24 bytes or greater can remotely crash Asterisk. -----
2009-09-05update to asterisk 1.2.35 which fixes AST-2009-006 -- IAX2 DOS vulnerabilityjnemeth3-7/+8
2009-08-23This update is just to fix a hypothetical security issue (AST-2009-005)jnemeth2-9/+6
which is most likely not exploitable.
2009-08-21regen (for DIST_SUBDIR change).wiz1-4/+4
2009-08-21Change DIST_SUBDIR to avoid people having to manually remove the oldjnemeth1-1/+3
distfile. Requested by wiz@.
2009-08-20bump PKGREVISION for previousjnemeth1-1/+2
2009-08-20Digium in its infinite wisdom changed the Music-On-Hold sound files in alljnemeth3-14/+17
release tarballs. Update for that change. While here, do some pkglint cleanup and add LICENSE=gplv2.
2009-07-22Remove empty PLIST.common_end.wiz1-1/+0
2009-06-14Remove @dirrm entries from PLISTsjoerg1-18/+1
2009-06-05Upgrade to 1.2.33. Provides a fix related to AST-2009-001.jnemeth2-6/+6
2009-05-15new MASTER_SITESjnemeth1-3/+3
2009-04-07Make it build on DragonFly master and recent versions of FreeBSD (probably).hasso2-7/+7
2009-01-26PR/38351 - Miro Voutilainen -- app_curl does not buildjnemeth4-7/+17
2009-01-22Need to care ${ASTVARLIBDIR}/sounds/priv-callerintros.obache2-5/+7
XXX: it should be in ${VARBASE}, not ${PREFIX}/libdata.
2009-01-21Update asterisk to 1.2.31.obache2-10/+9
While here, update MASTER_SITES and honor PKGMANDIR. ChangeLog-1.2.31: 2009-01-06 Leif Madsen <lmadsen@digium.com> * Asterisk 1.2.31 released 2009-01-06 20:44 +0000 [r167259] Tilghman Lesher <tlesher@digium.com> * channels/chan_iax2.c: Security fix AST-2009-001. 2008-12-10 Tilghman Lesher <tlesher@digium.com> * Asterisk 1.2.30.4 released 2008-12-10 21:06 +0000 [r162868] Tilghman Lesher <tlesher@digium.com> * channels/chan_iax2.c: Fix for AST-2008-012 2008-12-05 20:50 +0000 [r161421] Sean Bright <sean.bright@gmail.com> * include/asterisk/astobj2.h, astobj2.c: Fix build errors on FreeBSD (uint -> unsigned int). (closes issue #14006) Reported by: alphaque Patches: astobj2.h-patch uploaded by alphaque (license 259) (Slightly modified by seanbright) 2008-12-01 Tilghman Lesher <tlesher@digium.com> * Asterisk 1.2.30.3 released 2008-11-25 21:37 +0000 [r159245] Tilghman Lesher <tlesher@digium.com> * channels/chan_iax2.c: Regression fix for last security fix. Set the iseqno correctly. (closes issue #13918) Reported by: ffloimair Patches: 20081119__bug13918.diff.txt uploaded by Corydon76 (license 14) Tested by: ffloimair 2008-08-09 Tilghman Lesher <tlesher@digium.com> * Asterisk 1.2.30.2 released 2008-08-09 15:24 +0000 [r136945] Tilghman Lesher <tlesher@digium.com> * include/asterisk/compat.h, include/asterisk/astobj2.h: Regression fixes for Solaris 2008-07-25 15:00 +0000 [r133577] Russell Bryant <russell@digium.com> * LICENSE: Fix the IAX2 URI for calling Digium 2008-07-23 Tilghman Lesher <tlesher@digium.com> * Asterisk 1.2.30.1 released 2008-07-24 03:46 +0000 [r133360] Tilghman Lesher <tlesher@digium.com> * channels/chan_iax2.c: This part was not correctly patched for AST-2008-010.
2008-11-24- make sure rc.d script can find asterisk when it isn't in the pathjnemeth4-19/+21
- pkglint
2008-07-24Update Asterisk to version 1.2.30, fixing two Denial of Servicetonnerre2-7/+6
vulnerabilities (CVE-2008-3263 and CVE-2008-3264). cvs: ----------------------------------------------------------------------
2008-07-10Add reload command to rc.d script.sborrill2-6/+6
Remove sudo from rc.d - it should not be a requirement to stop your VoIP server.
2008-06-19Add missing file to PLIST. Bump PKGREVISION.wiz2-3/+4
2008-06-18pkgsrc-users, not packages (hi riz!)wiz1-2/+2
2008-06-13Update to 1.2.29. Security update.mjl3-8/+7
* channels/chan_sip.c: Copy the From header into a variable so that pedantic SIP handling does not try to mess with a NULL pointer. (AST-2008-008) * channels/chan_iax2.c: When we receive a full frame that is supposed to contain our call number, ensure that it has the correct one. (closes issue #10078) (AST-2008-006)
2008-06-12Add DESTDIR support.joerg1-1/+3
2008-06-07Stop pretending like I have time to maintain packages that I don'triz1-2/+2
even really use anymore.
2008-05-26Add INSTALLATION_DIRS so that installation is successful even in a bulkwiz1-1/+2
build.
2008-04-24Another try at fixing installation of the pkgconfig file under pbulk.wiz2-5/+5
2008-04-12Convert to use PLIST_VARS instead of manually passing "@comment "jlam2-17/+17
through PLIST_SUBST to the plist module.
2008-03-19Update asterisk to 1.2.27mjl2-7/+7
Update for several critical security issues: * astobj.h: Fix character string being treated as format string * chan_sip.c: Do not return with a successful authentication if the From header ends up empty. (AST-2008-003) * chan_iax2.c: Fix another potential seg fault (closes issue #11606) * chan_iax2.c: Fix a couple of places where it's possible to dereference a NULL pointer. * chan_sip.c, channels/chan_iax2.c: Fixing AST-2007-027 * cdr_pgsql.c: Properly escape src and dst fields (Fixes AST-2007-026)
2008-02-28Use REPLACE_BASH to make sure right bash is found for mkpkgconfig.wiz1-1/+2
2008-02-27Add bash to tools for mkpkgconfig.wiz1-2/+2
2008-02-20Create pkgconfig file in correct location. Add it to PLIST.wiz4-10/+20
Bump PKGREVISION.
2008-01-18Per the process outlined in revbump(1), perform a recursive revbumptnn1-1/+2
on packages that are affected by the switch from the openssl 0.9.7 branch to the 0.9.8 branch. ok jlam@
2007-08-10Update asterisk to 1.2.24.mjl2-6/+6
Version 1.2.24 is the final 1.2 release that contains normal bug fixes. The 1.2 branch will only be maintained with security fix releases from now until it is completely deprecated.
2007-08-03Update asterisk to 1.2.23mjl2-6/+6
* channels/chan_iax2.c: Don't create the Asterisk channel until we are starting the PBX on it. (ASA-2007-018) * channels/chan_agent.c: (closes issue #5866) Reported by: tyler Do not force channel format changes when a generator is present. The generator may have changed the formats itself and changing them back would cause issues. * channels/chan_sip.c: (closes issue #10236) Reported by: homesick Patches: rpid_1.4_75840.patch uploaded by homesick (license 91) Accept Remote Party ID on guest calls. * include/asterisk/app.h: We should not use C++ reserved words in API headers (closes issue #10266) * channels/chan_sip.c: Backport a fix for a memory leak that was fixed in trunk in reivision 76221 by rizzo. The memory used for the localaddr list was not freed during a configuration reload. * channels/chan_sip.c: (closes issue #10247) Reported by: fkasumovic Patches: chan_sip.patch uploaded by fkasumovic (license #101) Drop any peer realm authentication entries when reloading so multiple entries do not get added to the peer. * channels/chan_iax2.c: When processing full frames, take sequence number wraparound into account when deciding whether or not we need to request retransmissions by sending a VNAK. This code could cause VNAKs to be sent erroneously in some cases, and to not be sent in other cases when it should have been. (closes issue #10237, reported and patched by mihai) * channels/chan_iax2.c: When traversing the queue of frames for possible retransmission after receiving a VNAK, handle sequence number wraparound so that all frames that should be retransmitted actually do get retransmitted. (issue #10227, reported and patched by mihai) * apps/app_voicemail.c: Store prior to copy (closes issue #10193) * apps/app_queue.c: removed the word 'pissed' from ast_log(...)
2007-07-19Update to 1.2.22mjl4-15/+20
* channels/chan_skinny.c: Properly check for the length in the skinny packet to prevent an invalid memcpy. (ASA-2007-016) * channels/iax2-parser.h, channels/chan_iax2.c, channels/iax2-parser.c: Ensure that when encoding the contents of an ast_frame into an iax_frame, that the size of the destination buffer is known in the iax_frame so that code won't write past the end of the allocated buffer when sending outgoing frames. (ASA-2007-014) * channels/chan_iax2.c: After parsing information elements in IAX frames, set the data length to zero, so that code later on does not think it has data to copy. (ASA-2007-015) * res/res_musiconhold.c: Fix a couple potential minor memory leaks. load_moh_classes() could return without destroying the loaded configuration. * apps/app_chanspy.c: Fixed an issue where chanspy flags were uninitialized if no options were passed. * res/res_musiconhold.c: Ensure that adding a user to the list of users of a specific music on hold class is not done at the same time as any of the other operations on this list to prevent list corruption. * channels/chan_iax2.c: The function make_trunk() can fail and return -1 instead of a valid new call number. Fix the uses of this function to handle this instead of treating it as the new call number. This would cause a deadlock and memory corruption. * channels/chan_agent.c: The cli command "agent logoff Agent/x soft" did not work...at all. Now it does. * res/res_config_odbc.c: Make sure that the ESCAPE immediately follows the condition that uses LIKE. This fixes realtime extensions with ODBC. * apps/app_queue.c: Fix an issue where it was possible to have a service level of over 100% Between the time recalc_holdtime and update_queue was called, it was possible that the call could have been hungup. * dns.c: Use res_ndestroy on systems that have it. Otherwise, use res_nclose. This prevents a memleak on NetBSD - and possibly others.
2007-07-11Update asterisk to 1.2.21.1.mjl2-6/+6
2007-07-08Updated asterisk to 1.2.20mjl2-6/+6
This release is a regular maintenance release. It has been made just a couple of weeks after the previous set of releases because the development team has been working especially hard on fixing bugs lately. There has been a large volume of issues fixed in just two weeks.
2007-07-04Make it easier to build and install packages "unprivileged", wherejlam1-1/+3
the owner of all installed files is a non-root user. This change affects most packages that require special users or groups by making them use the specified unprivileged user and group instead. (1) Add two new variables PKG_GROUPS_VARS and PKG_USERS_VARS to unprivileged.mk. These two variables are lists of other bmake variables that define package-specific users and groups. Packages that have user-settable variables for users and groups, e.g. apache and APACHE_{USER,GROUP}, courier-mta and COURIER_{USER,GROUP}, etc., should list these variables in PKG_USERS_VARS and PKG_GROUPS_VARS so that unprivileged.mk can know to set them to ${UNPRIVILEGED_USER} and ${UNPRIVILEGED_GROUP}. (2) Modify packages to use PKG_GROUPS_VARS and PKG_USERS_VARS.
2007-06-24Updated asterisk to 1.2.19.mjl2-6/+6
2007-04-26Updated asterisk to 1.2.18mjl3-24/+29
This release contains a large number of fixes, including: - A recently published security vulnerability in the manager interface (ASA-2007-012) - Another recently published security vulnerability in the SIP channel driver (ASA-2007-011)
2007-03-22Upgrade to 1.2.17.mjl2-6/+6
Along with minor bug fixes, this release incorporates a fix for the SIP DoS vulnerability recently discovered by INRIA Lorraine. All users of Asterisk 1.2 with the SIP channel driver loaded and connected to an untrusted network are urged to update to this release to avoid the possibility of experiencing this problem. Note that the option "zaptel" won't compile any more since version 1.2.16. This needs an upgrade of the netbsd zaptel driver.
2007-03-07update to 1.2.16drochner2-6/+6
changes: 1.2.15: This release contains a significant Astribank (XPP) driver update, support for Digium's TE120P card, and various bug fixes. 1.2.16: This release contains a number of bug fixes, including a fix for a recently discovered security vulnerability. All Asterisk 1.2 users are urged to update to this release as soon as possible. This is in response to PR pkg/35924 by David Wetzel. The PR suggests to update to 1.4.1, but since I'm not using Asterisk myself I prefer to do just the minor update (which also fixes the security vulnerability) for now.
2006-12-20Update asterisk to 1.2.14.mjl4-8/+19
2006-11-01Make stopping asterisk actually work.mjl1-2/+3
2006-10-19Update to asterisk 1.2.13mjl2-6/+6
This release contains a fix for a security vulnerability recently found in the chan_skinny channel driver (for Cisco SCCP phones). This vulnerability would enable an attacker to remotely execute code as the system user running Asterisk (frequently 'root'). The exploit does not require that the skinny.conf contain any valid phone entries, only that chan_skinny is loaded and operational. This release also contains a number of bug fixes, and some improvements to the chan_sip channel driver (for SIP devices) to mitigate the impacts of a certain class of denial-of-service attacks that have recently been published. All Asterisk 1.2 users are urged to update to this release if they use the chan_skinny channel driver, or to stop loading it if it is not needed ('noload=>chan_skinny.so' in modules.conf will cause this behavior).
2006-09-16Add missing RCS Id.hira2-2/+4
2006-09-13Update asterisk to 1.2.12.1.mjl2-6/+6