Sun Feb 28 22:48:07 2021 UTC ()
asterisk13:  Update to Asterisk 13.38.2:

The Asterisk Development Team would like to announce security releases for
Asterisk 13, 16, 17 and 18, and Certified Asterisk 16.8. The available releases
are released as versions 13.38.2, 16.16.1, 17.9.2, 18.2.1 and 16.8-cert6.

These releases are available for immediate download at

https://downloads.asterisk.org/pub/telephony/asterisk/releases
https://downloads.asterisk.org/pub/telephony/certified-asterisk/releases

The following security vulnerabilities were resolved in these versions:

* AST-2021-001: Remote crash in res_pjsip_diversion
  If a registered user is tricked into dialing a

* AST-2021-002: Remote crash possible when negotiating T.38
  When

* AST-2021-003: Remote attacker could prematurely tear down SRTP calls
  An unauthenticated remote attacker could replay SRTP packets which could cause
  an Asterisk instance configured without strict RTP validation to tear down
  calls prematurely.

* AST-2021-004: An unsuspecting user could crash Asterisk with multiple
                hold/unhold requests
  Due to a signedness comparison mismatch, an authenticated WebRTC client could
  cause a stack overflow and Asterisk crash by sending multiple hold/unhold
  requests in quick succession.

* AST-2021-005: Remote Crash Vulnerability in PJSIP channel driver
  Given a scenario where an outgoing call is placed from Asterisk to a remote
  SIP server it is possible for a crash to occur.

For a full list of changes in the current releases, please see the ChangeLogs:

https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-13.38.2

The security advisories are available at:

https://downloads.asterisk.org/pub/security/AST-2021-001.pdf
https://downloads.asterisk.org/pub/security/AST-2021-002.pdf
https://downloads.asterisk.org/pub/security/AST-2021-003.pdf
https://downloads.asterisk.org/pub/security/AST-2021-004.pdf
https://downloads.asterisk.org/pub/security/AST-2021-005.pdf

Thank you for your continued support of Asterisk!


(jnemeth)
diff -r1.67 -r1.68 pkgsrc/comms/asterisk13/Makefile
diff -r1.17 -r1.18 pkgsrc/comms/asterisk13/distinfo

cvs diff -r1.67 -r1.68 pkgsrc/comms/asterisk13/Makefile (expand / switch to unified diff)

--- pkgsrc/comms/asterisk13/Makefile 2021/01/03 09:04:06 1.67
+++ pkgsrc/comms/asterisk13/Makefile 2021/02/28 22:48:07 1.68
@@ -1,21 +1,21 @@ @@ -1,21 +1,21 @@
1# $NetBSD: Makefile,v 1.67 2021/01/03 09:04:06 jnemeth Exp $ 1# $NetBSD: Makefile,v 1.68 2021/02/28 22:48:07 jnemeth Exp $
2# 2#
3# NOTE: when updating this package, there are two places that sound 3# NOTE: when updating this package, there are two places that sound
4# tarballs need to be checked; look in ${WRKSRC}/sounds/Makefile 4# tarballs need to be checked; look in ${WRKSRC}/sounds/Makefile
5# to find out the current sound file versions 5# to find out the current sound file versions
6 6
7DISTNAME= asterisk-13.38.1 7DISTNAME= asterisk-13.38.2
8PKGREVISION= 1 8#PKGREVISION= 1
9CATEGORIES= comms net audio 9CATEGORIES= comms net audio
10MASTER_SITES= http://downloads.asterisk.org/pub/telephony/asterisk/ 10MASTER_SITES= http://downloads.asterisk.org/pub/telephony/asterisk/
11MASTER_SITES+= http://downloads.asterisk.org/pub/telephony/asterisk/old-releases/ 11MASTER_SITES+= http://downloads.asterisk.org/pub/telephony/asterisk/old-releases/
12MASTER_SITES+= http://downloads.asterisk.org/pub/telephony/sounds/releases/ 12MASTER_SITES+= http://downloads.asterisk.org/pub/telephony/sounds/releases/
13DIST_SUBDIR= ${PKGNAME_NOREV} 13DIST_SUBDIR= ${PKGNAME_NOREV}
14DISTFILES= ${DEFAULT_DISTFILES} 14DISTFILES= ${DEFAULT_DISTFILES}
15 15
16COMMENT= The Asterisk Software PBX 16COMMENT= The Asterisk Software PBX
17LICENSE= gnu-gpl-v2 17LICENSE= gnu-gpl-v2
18 18
19EXTRACT_ONLY= ${DISTNAME}.tar.gz 19EXTRACT_ONLY= ${DISTNAME}.tar.gz
20OWNER= jnemeth@NetBSD.org 20OWNER= jnemeth@NetBSD.org
21HOMEPAGE= https://www.asterisk.org/ 21HOMEPAGE= https://www.asterisk.org/

cvs diff -r1.17 -r1.18 pkgsrc/comms/asterisk13/distinfo (expand / switch to unified diff)

--- pkgsrc/comms/asterisk13/distinfo 2021/01/02 22:45:43 1.17
+++ pkgsrc/comms/asterisk13/distinfo 2021/02/28 22:48:07 1.18
@@ -1,23 +1,23 @@ @@ -1,23 +1,23 @@
1$NetBSD: distinfo,v 1.17 2021/01/02 22:45:43 jnemeth Exp $ 1$NetBSD: distinfo,v 1.18 2021/02/28 22:48:07 jnemeth Exp $
2 2
3SHA1 (asterisk-13.38.1/asterisk-13.38.1.tar.gz) = 6a26385f1522db2b8ab927c76367ea717ff75117 3SHA1 (asterisk-13.38.2/asterisk-13.38.2.tar.gz) = 1e86b5b11c1053b0f6a7ec72a7e385aa356694f3
4RMD160 (asterisk-13.38.1/asterisk-13.38.1.tar.gz) = 5771cbdfd3ceca754f9c8df28ed29d52b35b143e 4RMD160 (asterisk-13.38.2/asterisk-13.38.2.tar.gz) = ad4ff2ef7f9c298f1bfcc8d28fc4600970d955a0
5SHA512 (asterisk-13.38.1/asterisk-13.38.1.tar.gz) = 270b7c8374104b3c2e9999503fa5cab5b465e37ddfa6759c1019fb99b6bb5877fe4505501ac3306a708ce911aeda36d04796f51156312c04fec013dbaa56a57f 5SHA512 (asterisk-13.38.2/asterisk-13.38.2.tar.gz) = bd9755503048cd8dcf8e39947dd5cfb617c20c4b1ad5033ae297499a4967c06ba11b6e43233c1ae0d33f8f11a81dbb9b4487f16a1f4786007172028caf1ee051
6Size (asterisk-13.38.1/asterisk-13.38.1.tar.gz) = 33705256 bytes 6Size (asterisk-13.38.2/asterisk-13.38.2.tar.gz) = 33708267 bytes
7SHA1 (asterisk-13.38.1/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 0207e289404704c42941759db9660269599044f9 7SHA1 (asterisk-13.38.2/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 0207e289404704c42941759db9660269599044f9
8RMD160 (asterisk-13.38.1/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 5d660e7664a56086bd60ad49196e1b622a60f106 8RMD160 (asterisk-13.38.2/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 5d660e7664a56086bd60ad49196e1b622a60f106
9SHA512 (asterisk-13.38.1/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 3f2f7bf3d5bce3544bc013f913c352f0204a3ce96239987403eb9dce8bc87e64a61d437762323a422a87b2fad1f3bf3e7a5f3d0d340f912a1b1dbfea9479d41d 9SHA512 (asterisk-13.38.2/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 3f2f7bf3d5bce3544bc013f913c352f0204a3ce96239987403eb9dce8bc87e64a61d437762323a422a87b2fad1f3bf3e7a5f3d0d340f912a1b1dbfea9479d41d
10Size (asterisk-13.38.1/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 4253587 bytes 10Size (asterisk-13.38.2/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 4253587 bytes
11SHA1 (patch-Makefile) = 7fb5c784cb5246d7b1ec9c586db8af1a9b9c5577 11SHA1 (patch-Makefile) = 7fb5c784cb5246d7b1ec9c586db8af1a9b9c5577
12SHA1 (patch-apps_app__dumpchan.c) = 127ac02bdc180ad2334cd095aa6e646feb6fba10 12SHA1 (patch-apps_app__dumpchan.c) = 127ac02bdc180ad2334cd095aa6e646feb6fba10
13SHA1 (patch-apps_app__followme.c) = c6a5790b5e9b34d07dbfdd66a58e2854c8c72695 13SHA1 (patch-apps_app__followme.c) = c6a5790b5e9b34d07dbfdd66a58e2854c8c72695
14SHA1 (patch-apps_app__queue.c) = ce9a0dd7a3534917f13642c9303336fbf908b8a9 14SHA1 (patch-apps_app__queue.c) = ce9a0dd7a3534917f13642c9303336fbf908b8a9
15SHA1 (patch-apps_app__sms.c) = ae81daf6ccf8c8fdf2251dba305e137bb9ab6b05 15SHA1 (patch-apps_app__sms.c) = ae81daf6ccf8c8fdf2251dba305e137bb9ab6b05
16SHA1 (patch-apps_app__voicemail.c) = ee46ffd64a15ef79fc568edd3d5eb68cd86865f7 16SHA1 (patch-apps_app__voicemail.c) = ee46ffd64a15ef79fc568edd3d5eb68cd86865f7
17SHA1 (patch-build__tools_mkpkgconfig) = 7fab8fcf46d9f8a3b98455674fec6307ec472b23 17SHA1 (patch-build__tools_mkpkgconfig) = 7fab8fcf46d9f8a3b98455674fec6307ec472b23
18SHA1 (patch-cdr_cdr__pgsql.c) = 02dc677126a8fb00b30f7f073a60b68942281dfe 18SHA1 (patch-cdr_cdr__pgsql.c) = 02dc677126a8fb00b30f7f073a60b68942281dfe
19SHA1 (patch-cel_cel__pgsql.c) = b280efab2b035ce60be268bac9bc8824910b2b8f 19SHA1 (patch-cel_cel__pgsql.c) = b280efab2b035ce60be268bac9bc8824910b2b8f
20SHA1 (patch-channels_chan__sip.c) = a4abe1dcdec3db719a7fd0e5dbefb9c12f6a37db 20SHA1 (patch-channels_chan__sip.c) = a4abe1dcdec3db719a7fd0e5dbefb9c12f6a37db
21SHA1 (patch-configure) = c2d002e886d83d8f578ae86ba4d457177ec09a01 21SHA1 (patch-configure) = c2d002e886d83d8f578ae86ba4d457177ec09a01
22SHA1 (patch-configure.ac) = fc91ab7d0e6ac72b9cd1ecfe653a1f6c2332a686 22SHA1 (patch-configure.ac) = fc91ab7d0e6ac72b9cd1ecfe653a1f6c2332a686
23SHA1 (patch-contrib_scripts_vmail.cgi) = 672827eedf315a82a289c82d1ae8b935166e9319 23SHA1 (patch-contrib_scripts_vmail.cgi) = 672827eedf315a82a289c82d1ae8b935166e9319