Path to this page:
Subject: CVS commit: pkgsrc/comms/asterisk
From: John Nemeth
Date: 2016-09-23 21:16:29
Message id: 20160923191629.992E9FBD1@cvs.NetBSD.org
Log Message:
Update to Asterisk 11.23.1: this is a security fix release to fix
AST-2016-007. Note that on Oct. 25th, this branch of Asterisk will
switch to security fixes, and one year later it will read end-of-life.
pkgsrc changes:
- don't use gethostbyname_r on NetBSD
- eliminate conflict with new hmac(1) function on NetBSd
----- AST-2016-007
The overlap dialing feature in chan_sip allows chan_sip to report
to a device that the number that has been dialed is incomplete and
more digits are required. If this functionality is used with a
device that has performed username/password authentication RTP
resources are leaked. This occurs because the code fails to release
the old RTP resources before allocating new ones in this scenario.
If all resources are used then RTP port exhaustion will occur and
no RTP sessions are able to be set up.
Files: