Subject: CVS commit: pkgsrc/comms/asterisk16
From: John Nemeth
Date: 2012-03-25 04:59:53
Message id: 20120325025953.D6BED175DD@cvs.netbsd.org

Log Message:
Update to 1.6.2.23:

This is a security fix update.  It fixes AST-2012-002.

NOTE NOTE NOTE

This is likely to be the last update to this package.  This version
of Asterisk will be EOLed on April 21st, 2012.  It will probably
be removed from pkgsrc not long after that.  If you are still using
this package, you should consider switching to comms/asterisk18,
the Long Term Support version, or comms/asterisk10 in the near
future.

NOTE NOTE NOTE

The Asterisk Development Team has announced security releases for
Asterisk 1.4, 1.6.2, 1.8, and 10. The available security releases
are released as versions 1.4.44, 1.6.2.23, 1.8.10.1, and 10.2.1.

The release of Asterisk 1.4.44 and 1.6.2.23 resolve an issue wherein
app_milliwatt can potentially overrun a buffer on the stack, causing
Asterisk to crash.  This does not have the potential for remote
code execution.

These issues and their resolution are described in the security
advisory.

For more information about the details of these vulnerabilities,
please read the security advisories AST-2012-002 and AST-2012-003,
which were released at the same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.6.2.23

The security advisories are available at:

 * http://downloads.asterisk.org/pub/security/AST-2012-002.pdf

Thank you for your continued support of Asterisk!

Files:
RevisionActionfile
1.39modifypkgsrc/comms/asterisk16/Makefile
1.26modifypkgsrc/comms/asterisk16/distinfo