Bug#884345: asterisk: CVE-2017-17664: Remote Crash Vulnerability in RTCP Stack

Bernhard Schmidt berni at debian.org
Fri Dec 29 18:40:05 UTC 2017


Control: fixed -1 1:13.18.5~dfsg-1

This was fixed in sid with the latest upload, but not properly closed in
the changelog.

asterisk (1:13.18.5~dfsg-1) unstable; urgency=medium

  * New upstream release:
    - CVE-2017-17850 / AST-2017-014 (closes: #885072)
    - AST-2017-012: Remote Crash Vulnerability in RTCP Stack
  * Re-add support for snmp (Closes #851738)
  * Don't load dundi, mgcp, skinny and unistim by default
  * Avoid parallel build in 'make install'
  * tests: realpath is now in coreutils
  * asttestmods: enable res_pjsip_pubsub tests
  * asttestmods: run asterisk as user asterisk
  * asttestmods: disable module test_cel for now

 -- Tzafrir Cohen <tzafrir at debian.org>  Thu, 28 Dec 2017 00:20:16 +0200

Bernhard



More information about the Pkg-voip-maintainers mailing list