summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* An intermittent explosion due to memory corruption was identified and ↵Tony Vroon2011-07-143-9/+16
| | | | | | patched by Jaco Kroon, closes bug #375141. Old ebuild killed. Package-Manager: portage-2.1.10.6/cvs/Linux x86_64
* Rediffed & revived backward compatibility patch by Erik Wallin closes bug ↵Tony Vroon2011-07-133-20/+19
| | | | | | #374947. Double-free and resulting segmentation fault reported by Jaco Kroon and fixed upstream by kpfleming, closes bug #375009. Old ebuild killed as it is unusable if HTTP is enabled on the management interface. Package-Manager: portage-2.1.10.5/cvs/Linux x86_64
* >=net-misc/asterisk-1.8.5 supports gmime-2.4. Bug #373505.Eray Aslan2011-07-123-9/+22
| | | | Package-Manager: portage-2.1.10.4/cvs/Linux x86_64
* Version bump; PUBLISH fixes now upstream. The channel variable backward ↵Tony Vroon2011-07-123-5/+453
| | | | | | compatibility patch no longer applies and has been dropped. Fixes a deadlock on attended transfer, thread blocking issue in SIP TCP/TLS, chanspy channel leak, MeetMe PIN prompts, stuck AGI scripts, lost MWI notifications & a conference crosstalk issue during the leader wait. Package-Manager: portage-2.1.10.4/cvs/Linux x86_64
* Regression fix by Jaco Kroon closes bug #374195. If you set DAHDI channel ↵Tony Vroon2011-07-063-5/+239
| | | | | | variables from your dial plan and this stopped working in 1.6.2.19; this is for you. Package-Manager: portage-2.1.10.4/cvs/Linux x86_64
* Actually install the newest init script with Jaco Kroon's restart fixes; as ↵Tony Vroon2011-07-044-8/+27
| | | | | | pointed out by Erik Wallin (reopened) bug #345307. Package-Manager: portage-2.1.10.4/cvs/Linux x86_64
* This is the final maintenance release in the 1.6.2 branch, which will ↵Tony Vroon2011-06-293-2/+240
| | | | | | receive security updates until April 21, 2012. The FullyBooted event is no longer erroneously broadcasted to all AMI connections. Resolves a thread blocking issue in SIP TCP/TLS, a chan_local crash, DTMF delays in core bridge and no longer offers video in directmedia unless both sides support it. Secured up to and including AST-2011-011. Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Remove last vulnerable ebuild in 1.6.2 branch now that stabling has been ↵Tony Vroon2011-06-293-239/+6
| | | | | | completed. For security bug #373409. Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* x86 stable, bug #373409Markus Meier2011-06-293-5/+18
| | | | Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* amd64 stable, bug #373409Kenneth Prugh2011-06-283-5/+8
| | | | Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Version bump to 1.6.2.18.2 for AST-2011-011 (information disclosure on ↵Tony Vroon2011-06-283-2/+235
| | | | | | valid/invalid SIP usernames even with alwaysauthreject). Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Trim down 1.8 branch by removing vulnerable 1.8.4.3 ebuild. Version bump to ↵Tony Vroon2011-06-283-15/+14
| | | | | | 1.8.4.4 for AST-2011-011. Information disclosure vulnerability; alwaysauthreject is not always effective resulting in different replies for non-existent SIP users than for a wrong password on a valid user. Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Changelog typo fix: 1.8 -> 1.6.2; more caffeine required.Tony Vroon2011-06-272-6/+6
| | | | Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Remove last vulnerable ebuild on 1.8 branch now that stabling has been ↵Tony Vroon2011-06-273-233/+10
| | | | | | completed for security bug #372793. Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* x86 stable wrt security bug #372793Paweł Hajdan2011-06-263-9/+13
| | | | Package-Manager: portage-2.1.9.42/cvs/Linux i686
* Mark stable on AMD64 based on arch testing by Agostino "ago" Sarubbo; for ↵Tony Vroon2011-06-243-8/+12
| | | | | | security bug #372793. Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Security update 1.6.2.18.1 resolves AST-2011-008 (buffer overflow due to ↵Tony Vroon2011-06-243-8/+18
| | | | | | NULL in SIP packet), AST-2011-009 (null pointer dereference due to missing left angle bracket in Contact header) & AST-2011-010 (unresolved pointer in IAX2 option control frame dereferenced by remote party). Remove one vulnerable non-stable ebuild. Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Trim down 1.8 branch by removing vulnerable ebuild. Security update 1.8.4.3 ↵Tony Vroon2011-06-243-8/+18
| | | | | | resolves AST-2011-008 (buffer overflow due to NULL in SIP packet), AST-2011-009 (null pointer dereference due to missing left angle bracket in Contact header) & AST-2011-010 (unresolved pointer in IAX2 option control frame dereferenced by remote party). Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
* Security update 1.8.4.2; upstream vulnerability report AST-2011-007 ↵Tony Vroon2011-06-063-5/+24
| | | | | | describes a remotely exploitable crash in the SIP channel driver. Remove vulnerable 1.8.4.1 ebuild; the 1.6.2 branch is not affected and remains the current stable. Package-Manager: portage-2.1.9.50/cvs/Linux x86_64
* Remove old 1.8 patches in files directory; a patch tarball has been used for ↵Tony Vroon2011-06-0111-331/+15
| | | | | | a while now. Package-Manager: portage-2.1.9.49/cvs/Linux x86_64
* Clean up older ebuilds and USE-flag description for misdn in preparation for ↵Tony Vroon2011-05-275-883/+11
| | | | | | unmasking. Package-Manager: portage-2.1.9.49/cvs/Linux x86_64
* Bugfix release; Cisco 79xx phones now register again. Unreachable TCP/TLS ↵Tony Vroon2011-05-263-5/+452
| | | | | | peers no longer cause the SIP stack to explode. Snom phones can now reliably register over TLS. Upstream patch scavenged to prevent PUBLISH dialogs accumulating. Package-Manager: portage-2.1.9.49/cvs/Linux x86_64
* QA: ensure presence of dialout group. Fix install when using new, ↵Diego Elio Pettenò2011-05-256-13/+23
| | | | | | OpenRC/Baselayout2-native stages that lack such group. Package-Manager: portage-2.2.0_alpha35/cvs/Linux x86_64
* Bugfix release, with directmedia codecs that only 1 side supports are no ↵Tony Vroon2011-05-133-5/+239
| | | | | | longer offered. Several DTMF transfer fixes and SIP deadlock fixes. Channel soft hangup fixes relevant to redirects out of MeetMe. Distro patchset unchanged. Package-Manager: portage-2.1.9.49/cvs/Linux x86_64
* Build additional utilities like smsq as suggested by Nico Baggus in bug ↵Tony Vroon2011-05-133-2/+458
| | | | | | #358001. Fix up dodoc call and drop broken misdn support, bugs #360141 & #360143 by Agostino "ago" Sarubbo. Apply patch for upstream bug #19192, as diagnosed by Stefan "stkn" Knoblich. Package-Manager: portage-2.1.9.49/cvs/Linux x86_64
* Removed vulnerable ebuild for CVE-2011-{1507,1599}, security bug #364887.Tony Vroon2011-04-283-238/+5
| | | | Package-Manager: portage-2.1.9.46/cvs/Linux x86_64
* x86 stable per bug 364887Thomas Kahle2011-04-281-6/+6
| | | | | Package-Manager: portage-2.1.9.46/cvs/Linux i686 Manifest-Sign-Key: 0x20F2A3AE
* x86 stable per bug 364887Thomas Kahle2011-04-282-3/+6
| | | | Package-Manager: portage-2.1.9.46/cvs/Linux i686
* Mark stable on AMD64 for security bug #364887. Arch testing by Agostino ↵Tony Vroon2011-04-263-8/+12
| | | | | | "ago" Sarubbo. Package-Manager: portage-2.1.9.46/cvs/Linux x86_64
* Make dependency on newer DAHDI explicit to avoid surprises for the X86 team.Tony Vroon2011-04-262-3/+6
| | | | Package-Manager: portage-2.1.9.46/cvs/Linux x86_64
* Fast-track AMD64 stable for security bug #364887. Testing by Agostino "ago" ↵Tony Vroon2011-04-261-5/+5
| | | | | | Sarubbo. Package-Manager: portage-2.1.9.46/cvs/Linux x86_64
* Update in 1.6.2 branch for security bug #364887 by Tim Sammut. Addresses ↵Tony Vroon2011-04-263-5/+238
| | | | | | CVE-2011-1507 (AST-2011-005/AST-2011-006) and is planned for fast-track stabilisation. Package-Manager: portage-2.1.9.46/cvs/Linux x86_64
* Update in 1.8 branch for AST-2011-005 & AST-2011-006 (resource exhaustion & ↵Tony Vroon2011-04-263-8/+15
| | | | | | unauthenticated shell access, respectively). Remove vulnerable ebuild. Package-Manager: portage-2.1.9.46/cvs/Linux x86_64
* Depend on a logger (at runtime) instead of depending on syslog-ng, as it ↵Diego Elio Pettenò2011-04-073-8/+16
| | | | | | does not use any logger-specific interfaces (nor requires one to be present for build). Close bug #362433. Package-Manager: portage-2.2.0_alpha29/cvs/Linux x86_64
* Remove vulnerable ebuild for CVE-2011-1174 & CVE-2011-1175 now that a secure ↵Tony Vroon2011-03-233-231/+9
| | | | | | ebuild has been stabled. Package-Manager: portage-2.1.9.44/cvs/Linux x86_64
* x86 stable per bug 359767Thomas Kahle2011-03-233-9/+12
| | | | Package-Manager: portage-2.1.9.44/cvs/Linux i686
* Stable on amd64 wrt bug #359767Christoph Mende2011-03-233-9/+12
| | | | Package-Manager: portage-2.2.0_alpha28/cvs/Linux x86_64
* Secure ebuild for the 1.6.2 branch; robustness fixes for the manager ↵Tony Vroon2011-03-233-8/+19
| | | | | | interface. As per advisory AST-2011-003, a denial of service is possible through resource exhaustion in previous versions. As per advisory AST-2011-004, it is possible to cause a NULL pointer dereference by rapidly opening & closing TCP/TLS connections. Removed all but the last stable ebuild. For security bug #359767 filed by Pawel Hajdan, Jr. Package-Manager: portage-2.1.9.44/cvs/Linux x86_64
* Secure ebuild for the 1.8 branch; robustness fixes for the manager ↵Tony Vroon2011-03-234-442/+18
| | | | | | interface. As per advisory AST-2011-003, a denial of service is possible through resource exhaustion in previous versions. As per advisory AST-2011-004, it is possible to cause a NULL pointer dereference by rapidly opening & closing TCP/TLS connections. Removed insecure ebuilds. Package-Manager: portage-2.1.9.44/cvs/Linux x86_64
* New release on the 1.6.2 branch. This is a bugfix release, the official ↵Tony Vroon2011-02-283-5/+237
| | | | | | changelog is at http://www.asterisk.org/node/51583 for your enjoyment. Package-Manager: portage-2.1.9.41/cvs/Linux x86_64
* New release on the 1.8 branch. This is a bugfix release, the official ↵Tony Vroon2011-02-283-5/+445
| | | | | | changelog is at http://www.asterisk.org/node/51584 for your enjoyment. Package-Manager: portage-2.1.9.41/cvs/Linux x86_64
* Remove insecure ebuilds now that security stabilisation has been completed. ↵Tony Vroon2011-02-2719-2482/+21
| | | | | | Arch teams have signed off on their loss of keywording for this package. Package-Manager: portage-2.1.9.41/cvs/Linux x86_64
* Mark stable on AMD64 for security bug #352059. Arch testing by Agostino ↵Tony Vroon2011-02-272-3/+7
| | | | | | | "ago" Sarubbo. Package-Manager: portage-2.1.9.41/cvs/Linux x86_64 RepoMan-Options: --force
* Mark stable on AMD64 for security bug #352059. Arch testing by Agostino ↵Tony Vroon2011-02-271-5/+5
| | | | | | "ago" Sarubbo. Package-Manager: portage-2.1.9.41/cvs/Linux x86_64
* Transfer stable X86 keyword from -r1 to -r2; removing defective keepsrc ↵Tony Vroon2011-02-264-27/+16
| | | | | | | USE-flag from ebuild & metadata.xml now. Removal of 1.2 & 1.4 is immanent. Package-Manager: portage-2.1.9.41/cvs/Linux x86_64 RepoMan-Options: --force
* x86 stable per bug 352059Thomas Kahle2011-02-262-3/+6
| | | | | Package-Manager: portage-2.1.9.40/cvs/Linux i686 RepoMan-Options: --force
* x86 stable per bug 352059Thomas Kahle2011-02-261-5/+5
| | | | Package-Manager: portage-2.1.9.40/cvs/Linux i686
* Drop problematic misdn dependencies from the 1.6.2 branch to aid in security ↵Tony Vroon2011-02-243-12/+16
| | | | | | | stabilisation. Both the 1.2 and the 1.4 branch are slated for removal and will be masked soon. Package-Manager: portage-2.1.9.40/cvs/Linux x86_64 RepoMan-Options: --force
* Trim down 1.6.2 branch by culling vulnerable ebuild for AST-2011-002.Tony Vroon2011-02-223-8/+14
| | | | | Package-Manager: portage-2.1.9.40/cvs/Linux x86_64 RepoMan-Options: --force
* Trim down 1.8 branch by culling vulnerable ebuilds for AST-2011-002. Adding ↵Tony Vroon2011-02-224-441/+17
| | | | | | | 1.8.2.4 which fixes overflows in both stack & heap based arrays that can be exploited through specially crafted UDPTL packets, particularly for T.38 pass-through & termination. Package-Manager: portage-2.1.9.40/cvs/Linux x86_64 RepoMan-Options: --force