[Pkg-voip-commits] r7872 - /asterisk/branches/lenny/debian/changelog

paravoid at alioth.debian.org paravoid at alioth.debian.org
Sun Dec 6 18:59:18 UTC 2009


Author: paravoid
Date: Sun Dec  6 18:59:17 2009
New Revision: 7872

URL: http://svn.debian.org/wsvn/pkg-voip/?sc=1&rev=7872
Log:
Put AST-2009-010 to the security fixes section

Modified:
    asterisk/branches/lenny/debian/changelog

Modified: asterisk/branches/lenny/debian/changelog
URL: http://svn.debian.org/wsvn/pkg-voip/asterisk/branches/lenny/debian/changelog?rev=7872&op=diff
==============================================================================
--- asterisk/branches/lenny/debian/changelog (original)
+++ asterisk/branches/lenny/debian/changelog Sun Dec  6 18:59:17 2009
@@ -10,6 +10,8 @@
     - Stop shipping old static-http code in examples. Among other things, it
       includes a vulnerable version of the prototype Javascript library.
       AST-2009-009, CVE-2008-7220. (Closes: #554486)
+    - "RTP Remote Crash Vulnerability", AST-2009-010,CVE-2009-4055.
+      (Closes: #559103)
   * Fix broken IAX2 sequence number generation, an upstream regression of
     AST-2008-010's fix, included in the previous release of ours.
   * Backport a patch that fixes severe problems when using IAX2 encryption.
@@ -23,8 +25,6 @@
   * Create the /usr/share/asterisk/agi-bin directory. (Closes: #463983)
   * Use a disabled [directories] in asterisk.conf rather than an invalid
     [globals] (Closes: #532313).
-  * Fix for AST-2009-010 (CVE-2009-4055) - Long RTP comfort noise bug
-    (Closes: #559103).
 
  -- Faidon Liambotis <paravoid at debian.org>  Mon, 30 Nov 2009 05:26:29 +0200
 




More information about the Pkg-voip-commits mailing list