Merge asterisk 1:1.8.4.4~dfsg-2 (universe) from Debian unstable (main)

Bug #852479 reported by Dave Walker
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
asterisk (Ubuntu)
Fix Released
Wishlist
James Page

Bug Description

Please merge asterisk 1:1.8.4.4~dfsg-2 (universe) from Debian unstable (main)

Includes a number of serious bug fixes, also includes a new upstream bug-fix only point release.

Thanks.

Changelog entries since current oneiric version 1:1.8.3.3-1ubuntu1:

asterisk (1:1.8.4.4~dfsg-2) unstable; urgency=low

  * Don't mark en-gsm sound files as enabled, so they won't be downloaded.

 -- Tzafrir Cohen <email address hidden> Mon, 04 Jul 2011 23:19:50 +0300

asterisk (1:1.8.4.4~dfsg-1) unstable; urgency=high

  * AST-2011-011 (CVE-2011-2536): Don't leak SIP username information
    (closes: #632029)
  * Clearly the NC-ND license for AST.{pdf,txt} is here to stay. Strip it.
    - And while we're at at, strip out sound files and some generated files.

 -- Tzafrir Cohen <email address hidden> Fri, 01 Jul 2011 11:51:45 +0300

asterisk (1:1.8.4.3-1) unstable; urgency=high

  * New upstream point release, fixes 3 remotely-explitables (of sort) bugs:
    - AST-2011-008, CVE-2011-2529 (Closes: #631446)
    - AST-2011-009 (Closes: #631445)
    - AST-2011-010, CVE-2011-2535 (Closes: #631448)

 -- Tzafrir Cohen <email address hidden> Fri, 24 Jun 2011 00:51:49 +0300

asterisk (1:1.8.4.2-1) unstable; urgency=low

  * New upstream point release:
    - Fixes CVE-2011-2216 - AST-2011-007 (Closes: #629130).
  * Patch gcc46: Fix the induced regression.
  * Blacklist SRTP support on Sparc and hurd-i386 until SRTP available there.

 -- Tzafrir Cohen <email address hidden> Fri, 03 Jun 2011 23:20:29 +0300

asterisk (1:1.8.4-1) unstable; urgency=low

  * New upstream release.
    - Patch no_ssl2 removed: merged upstream.
  * Remove unneeded dependency on voicemail modules - only leave Recommends
    (Closes: #624190).
  * Patch refix_bashism: bashism crept bact into the configure script
    (Jilles Tjoelker).
  * Fixes for kFreeBSD (Closes: #624569):
    - Declare build-deps linux-any: libtonezone-dev, libvpb-dev,
      libbluetooth-dev, libopenh323-dev, libcap[2]-dev, libstrp0-dev.
    - Thus sub-packages asterisk-dahdi, asterisk-h323 and asterisk-mobile
      are linux-any.
    - And logic added to rules file not to copy their files on non-linux.
    - Patch kfreebsd: Fix building with kFreeBSD.
    - Patch no_uname: Fix building with kFreeBSD: an uglier patch.
  * Patch gcc46: Some gcc-4.6 fixes from upstream. Get rid of some
    build warnings.

 -- Tzafrir Cohen <email address hidden> Mon, 16 May 2011 00:58:19 +0300

Tags: server-o-rs
Dave Walker (davewalker)
Changed in asterisk (Ubuntu):
importance: Undecided → Wishlist
status: New → Confirmed
tags: added: server-o-rs
James Page (james-page)
Changed in asterisk (Ubuntu):
status: Confirmed → In Progress
assignee: nobody → James Page (james-page)
Revision history for this message
Dave Walker (davewalker) wrote :

The merge is too large to give an accurate review, but sniff testing looks good; and balancing Security, High and Medium bugs it resolves makes it a good candidate.

Uploading.

Thanks.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package asterisk - 1:1.8.4.4~dfsg-2ubuntu1

---------------
asterisk (1:1.8.4.4~dfsg-2ubuntu1) oneiric; urgency=low

  * Merge from debian unstable (LP: #852479). Remaining changes:
    - debian/control: Build-depend on hardening-wrapper
    - debian/rules: Make use of hardening-wrapper
    - debian/asterisk.init: chown /dev/dahdi
    - debian/backports/hardy: add file
    - debian/backports/asterisk.init.hardy: add file
  * Changes dropped from Ubuntu delta as no longer applicable:
    - debian/control:
      + Removed Uploaders field
      + Removed Debian Vcs-Svn entry and replaced with ubuntu-voip Vcs-Bzr,
        to reflect divergence in packages.

asterisk (1:1.8.4.4~dfsg-2) unstable; urgency=low

  * Don't mark en-gsm sound files as enabled, so they won't be downloaded.

asterisk (1:1.8.4.4~dfsg-1) unstable; urgency=high

  * AST-2011-011 (CVE-2011-2536): Don't leak SIP username information
    (closes: #632029)
  * Clearly the NC-ND license for AST.{pdf,txt} is here to stay. Strip it.
    - And while we're at at, strip out sound files and some generated files.

asterisk (1:1.8.4.3-1) unstable; urgency=high

  * New upstream point release, fixes 3 remotely-explitables (of sort) bugs:
    - AST-2011-008, CVE-2011-2529 (Closes: #631446)
    - AST-2011-009 (Closes: #631445)
    - AST-2011-010, CVE-2011-2535 (Closes: #631448)

asterisk (1:1.8.4.2-1) unstable; urgency=low

  * New upstream point release:
    - Fixes CVE-2011-2216 - AST-2011-007 (Closes: #629130).
  * Patch gcc46: Fix the induced regression.
  * Blacklist SRTP support on Sparc and hurd-i386 until SRTP available there.

asterisk (1:1.8.4-1) unstable; urgency=low

  * New upstream release.
    - Patch no_ssl2 removed: merged upstream.
  * Remove unneeded dependency on voicemail modules - only leave Recommends
    (Closes: #624190).
  * Patch refix_bashism: bashism crept bact into the configure script
    (Jilles Tjoelker).
  * Fixes for kFreeBSD (Closes: #624569):
    - Declare build-deps linux-any: libtonezone-dev, libvpb-dev,
      libbluetooth-dev, libopenh323-dev, libcap[2]-dev, libstrp0-dev.
    - Thus sub-packages asterisk-dahdi, asterisk-h323 and asterisk-mobile
      are linux-any.
    - And logic added to rules file not to copy their files on non-linux.
    - Patch kfreebsd: Fix building with kFreeBSD.
    - Patch no_uname: Fix building with kFreeBSD: an uglier patch.
  * Patch gcc46: Some gcc-4.6 fixes from upstream. Get rid of some
    build warnings.
 -- James Page <email address hidden> Tue, 20 Sep 2011 14:05:14 +0100

Changed in asterisk (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.