# ChangeLog for net-misc/asterisk # Copyright 1999-2013 Gentoo Foundation; Distributed under the GPL v2 # $Header: /var/cvsroot/gentoo-x86/net-misc/asterisk/ChangeLog,v 1.467 2013/12/23 12:27:52 chainsaw Exp $ 23 Dec 2013; Tony Vroon -asterisk-1.8.23.1.ebuild, -asterisk-1.8.24.0.ebuild, -asterisk-11.5.1.ebuild, -asterisk-11.6.0.ebuild, -asterisk-11.6.0-r1.ebuild: Remove all vulnerable ebuilds for AST-2013-006 & AST-2013-007; for security bug #494630. 23 Dec 2013; Agostino Sarubbo asterisk-1.8.25.0.ebuild, asterisk-11.7.0.ebuild: Stable for x86, wrt bug #494630 23 Dec 2013; Agostino Sarubbo asterisk-1.8.25.0.ebuild, asterisk-11.7.0.ebuild: Stable for amd64, wrt bug #494630 *asterisk-11.7.0 (18 Dec 2013) *asterisk-1.8.25.0 (18 Dec 2013) 18 Dec 2013; Tony Vroon +asterisk-1.8.25.0.ebuild, +asterisk-11.7.0.ebuild: Upgrades on both branches for memory corruption (AST-2013-006) & security bypass (AST-2013-007) vulnerabilities, as per Agostino Sarubbo in security bug #494630. Squelch unnecessary chatter from build system, as per Patryk Rzadzinski in bug #489862. *asterisk-11.6.0-r1 (30 Oct 2013) 30 Oct 2013; Tony Vroon +asterisk-11.6.0-r1.ebuild: A useful response to the debug USE-flag, as suggested by Kerin Millar and implemented by Jaco Kroon. Closes bug #346959. 27 Oct 2013; Pacho Ramos metadata.xml: Voip herd is removed: http://article.gmane.org/gmane.linux.gentoo.devel/88434 *asterisk-1.8.24.0 (22 Oct 2013) 22 Oct 2013; Tony Vroon +asterisk-1.8.24.0.ebuild: Version bump. *asterisk-11.6.0 (22 Oct 2013) 22 Oct 2013; Tony Vroon +asterisk-11.6.0.ebuild: Version bump. Features improved NAT support and plugs a memory leak in the logger. 28 Aug 2013; Agostino Sarubbo -asterisk-1.8.20.2.ebuild, -asterisk-11.2.2.ebuild: Remove old 28 Aug 2013; Agostino Sarubbo asterisk-1.8.23.1.ebuild, asterisk-11.5.1.ebuild: Stable for x86, wrt bug #482776 28 Aug 2013; Agostino Sarubbo asterisk-1.8.23.1.ebuild, asterisk-11.5.1.ebuild: Stable for amd64, wrt bug #482776 *asterisk-11.5.1 (28 Aug 2013) *asterisk-1.8.23.1 (28 Aug 2013) 28 Aug 2013; Tony Vroon -asterisk-1.8.22.0.ebuild, -asterisk-1.8.23.0.ebuild, +asterisk-1.8.23.1.ebuild, -asterisk-11.4.0.ebuild, -asterisk-11.5.0.ebuild, +asterisk-11.5.1.ebuild, +files/1.8.0/asterisk.initd7: Security upgrades for AST-2013-004 & AST-2013-005 on both branches. Behavioral improvements for G729 VAD, closes bug #480928. Add missed ownership checks to init script, closes bug #482688. Both by Jaco Kroon. Removed all insecure non-stable ebuilds. 31 Jul 2013; Tony Vroon asterisk-1.8.20.2.ebuild, -asterisk-1.8.21.0.ebuild, asterisk-1.8.22.0.ebuild, asterisk-1.8.23.0.ebuild, asterisk-11.2.2.ebuild, -asterisk-11.3.0.ebuild, asterisk-11.4.0.ebuild, asterisk-11.5.0.ebuild: Make our inability to co-exist with net-libs/pjsip explicit to avoid any build failures. Closes bug #47812 by Steven Lai. Removed older non-stable builds on both branches. *asterisk-11.5.0 (23 Jul 2013) *asterisk-1.8.23.0 (23 Jul 2013) 23 Jul 2013; Tony Vroon +asterisk-1.8.23.0.ebuild, +asterisk-11.5.0.ebuild, +files/1.8.0/asterisk.initd6: Bugfix releases on both branches. Completely revised init script by Jaco Kroon that supports running multiple Asterisk instances on a single host, closes bug #473224. *asterisk-1.8.22.0 (20 May 2013) 20 May 2013; Tony Vroon +asterisk-1.8.22.0.ebuild: One of the last bugfix releases on the 1.8 branch. You need to migrate to 11. And soon. *asterisk-11.4.0 (20 May 2013) 20 May 2013; Tony Vroon +asterisk-11.4.0.ebuild: In a refreshing change of heart, upstream now care about parallel build failures. Drop our relevant two downstream patches. Fixes a res_timing_pthread deadlock, an FD leak in the web server and more SRTP decryption/white noise issues. 30 Mar 2013; Tony Vroon -asterisk-1.8.20.1.ebuild, -asterisk-11.2.1.ebuild: Remove vulnerable ebuilds after stabling, for security bug #463622. 30 Mar 2013; Agostino Sarubbo asterisk-1.8.20.2.ebuild, asterisk-11.2.2.ebuild: Stable for x86, wrt bug #463622 30 Mar 2013; Agostino Sarubbo asterisk-1.8.20.2.ebuild, asterisk-11.2.2.ebuild: Stable for amd64, wrt bug #463622 *asterisk-11.3.0 (29 Mar 2013) *asterisk-1.8.21.0 (29 Mar 2013) 29 Mar 2013; Tony Vroon +asterisk-1.8.21.0.ebuild, +asterisk-11.3.0.ebuild: Bugfix releases on both branches. Native RTP bridging is no longer attempted if packetisation differs, this helps to prevent fax failures. Improved locking to prevent deadlocks. *asterisk-11.2.2 (28 Mar 2013) *asterisk-1.8.20.2 (28 Mar 2013) 28 Mar 2013; Tony Vroon -asterisk-1.8.19.1.ebuild, -asterisk-1.8.20.0.ebuild, +asterisk-1.8.20.2.ebuild, -asterisk-11.1.2.ebuild, -asterisk-11.2.0.ebuild, -asterisk-11.2.1-r2.ebuild, +asterisk-11.2.2.ebuild: Security upgrade to address a boundary error in H264 video SDP handling, naive Content-Length variable parsing in HTTP POST requests and an information leak around account existence for the SIP channel driver. *asterisk-11.2.1-r2 (06 Mar 2013) 06 Mar 2013; Tony Vroon -asterisk-11.2.1-r1.ebuild, +asterisk-11.2.1-r2.ebuild: Stop installing the /var/run directory structure, closes bug #451808. Two additional stability fixes, closes bug #460568. Removing -r1 ebuild as the reload protections within it are incomplete. Use -r2 or last stable. All patching by Jaco Kroon. *asterisk-11.2.1-r1 (05 Mar 2013) 05 Mar 2013; Tony Vroon +asterisk-11.2.1-r1.ebuild: Fix by Jaco Kroon to correctly handle error returns for dundi lookups, previously resulting in segmentation faults. Closes bug #460406. 26 Feb 2013; Agostino Sarubbo asterisk-11.2.1.ebuild: Stable for x86, wrt bug #458126 26 Feb 2013; Agostino Sarubbo asterisk-11.2.1.ebuild: Stable for amd64, wrt bug #458126 12 Feb 2013; Agostino Sarubbo asterisk-1.8.20.1.ebuild: Stable for x86, wrt bug #456936 12 Feb 2013; Agostino Sarubbo asterisk-1.8.20.1.ebuild: Stable for amd64, wrt bug #456936 *asterisk-11.2.1 (24 Jan 2013) *asterisk-1.8.20.1 (24 Jan 2013) 24 Jan 2013; Tony Vroon +files/1.8.0/asterisk.initd5, -files/1.8.0/asterisk.initd, -files/1.8.0/asterisk.initd2, -files/1.8.0/asterisk.initd3, +asterisk-1.8.20.1.ebuild, +asterisk-11.2.1.ebuild: Partial rewrite of the init script by Jaco Kroon addresses shortcomings identified by Vincent Brillault in bug #445176. Upstream fixes include an astcanary PID mix-up and a necessary reset of the RTP sequence counter when SSRC changes. *asterisk-1.8.20.0 (15 Jan 2013) 15 Jan 2013; Tony Vroon +asterisk-1.8.20.0.ebuild: Bugfix release on the 1.8 branch. The fix for bug #440278 is now upstream. *asterisk-11.2.0 (15 Jan 2013) 15 Jan 2013; Tony Vroon +asterisk-11.2.0.ebuild: Bugfix release on the 11 branch. The fix for bug #440278 is now upstream. *asterisk-11.1.2 (07 Jan 2013) 07 Jan 2013; Tony Vroon -asterisk-11.1.1.ebuild, +asterisk-11.1.2.ebuild: One final unsafe use of TCP reads onto the stack in res_xmpp; also stops caching taking place where unnecessary. This completes the DoS protection intended for 11.1.1; removing unsafe ebuild from tree. 04 Jan 2013; Tony Vroon asterisk-1.8.19.1.ebuild, asterisk-11.1.1.ebuild: Remove /var/run keepdir statements as per Diego Elio Pettenò in bug #450222. 04 Jan 2013; Tony Vroon -asterisk-10.11.1.ebuild: As previously announced the 10 branch of Asterisk is now being removed. For stable releases, you want the 1.8 branch. For an actively developed branch with more features, you want the 11 branch. 03 Jan 2013; Tony Vroon -asterisk-1.8.18.0-r2.ebuild: Clear vulnerable ebuild in 1.8 branch now that stabling has completed. 03 Jan 2013; Agostino Sarubbo asterisk-1.8.19.1.ebuild: Stable for amd64, wrt bug #449828 03 Jan 2013; Andreas Schuerch asterisk-1.8.19.1.ebuild: x86 stable, see bug 449828 *asterisk-11.1.1 (02 Jan 2013) *asterisk-10.11.1 (02 Jan 2013) *asterisk-1.8.19.1 (02 Jan 2013) 02 Jan 2013; Tony Vroon -asterisk-1.8.15.1.ebuild, -asterisk-1.8.18.1.ebuild, -asterisk-1.8.19.0.ebuild, +asterisk-1.8.19.1.ebuild, -asterisk-10.10.1.ebuild, -asterisk-10.11.0.ebuild, +asterisk-10.11.1.ebuild, -asterisk-11.0.2.ebuild, -asterisk-11.1.0.ebuild, +asterisk-11.1.1.ebuild: Security releases on all three branches; stop using stack allocations in TCP receive paths, as multiple packets may be concatenated together and overflow the stack as a result (CVE-2012-5976 / AST-2012-015). Never cache devices that are not associated with a physical entity, as to do so allows a denial of service through cache exhaustion (CVE-2012-5977 / AST-2012-014). Remove all non-stable vulnerable ebuilds. As requested by Sean Amoss in bug #449828. 01 Jan 2013; Andreas K. Huettel +ChangeLog-2012: Split ChangeLog. For previous entries, please see ChangeLog-2012.