-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 10 Feb 2011 17:06:37 +0200 Source: asterisk Binary: asterisk asterisk-h323 asterisk-doc asterisk-dev asterisk-dbg asterisk-sounds-main asterisk-config Architecture: amd64 Version: 1:1.4.21.2~dfsg-3+lenny2 Distribution: lenny-security Urgency: high Maintainer: amd64 Builddd Daemon (barber) Changed-By: Faidon Liambotis Description: asterisk - Open Source Private Branch Exchange (PBX) asterisk-config - Configuration files for Asterisk asterisk-dbg - Debugging symbols for Asterisk asterisk-dev - Development files for Asterisk asterisk-doc - Source code documentation for Asterisk asterisk-h323 - H.323 protocol support for Asterisk asterisk-sounds-main - Core Sound files for Asterisk (English) Closes: 610487 Changes: asterisk (1:1.4.21.2~dfsg-3+lenny2) oldstable-security; urgency=high . [ Tzafrir Cohen ] * AST-2011-001/CVE-2011-0495: Stack buffer overflow in SIP channel driver (Closes: #610487) * Backport a one-liner patch from upstream (ast_uri_validhex) to successfully apply the AST-2011-001 patch. Checksums-Sha1: 41b8cab6e66ae8337672b792cf1c96a32eb6fff2 2628450 asterisk_1.4.21.2~dfsg-3+lenny2_amd64.deb 21ca952246642840bf8af85d5a1b8c87839adfa0 398638 asterisk-h323_1.4.21.2~dfsg-3+lenny2_amd64.deb 059e1cda7afc35e266858756105eae5c67ca61ef 13087986 asterisk-dbg_1.4.21.2~dfsg-3+lenny2_amd64.deb Checksums-Sha256: 01135915e4a95f531d77472a3edf349374bab6cec2c58a496ea9623a36d81a14 2628450 asterisk_1.4.21.2~dfsg-3+lenny2_amd64.deb a6de98fee77e0b6cd03b35c3b65765003e4aa9db71826261148dba3b295dd4be 398638 asterisk-h323_1.4.21.2~dfsg-3+lenny2_amd64.deb 134e269beefa3ed563cbd6dfd200a1b59c6cd93a96c6fb019eac288cbfe198b8 13087986 asterisk-dbg_1.4.21.2~dfsg-3+lenny2_amd64.deb Files: 2a48edbd7a1cc920430fba9c6d70b7b7 2628450 comm optional asterisk_1.4.21.2~dfsg-3+lenny2_amd64.deb bafb66ab706d7e1df1679861fdba2daf 398638 comm optional asterisk-h323_1.4.21.2~dfsg-3+lenny2_amd64.deb adde0cd592ca05d3322e2ebcb1da1597 13087986 devel extra asterisk-dbg_1.4.21.2~dfsg-3+lenny2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk1ZcOwACgkQXm3vHE4uylpuOACfcIuRQZ2WYAFvAQJjtiNSw44O zXwAoJhvMJdAj6HuvEd9aSN8FSVwT/on =8+Id -----END PGP SIGNATURE-----