Bug#1024353: asterisk: segfault with the latest security update

sergio sergio+it at outerface.net
Fri Nov 18 07:49:20 GMT 2022


Package: asterisk
Version: 1:16.28.0~dfsg-0+deb11u1
Severity: important
X-Debbugs-Cc: team at security.debian.org

Dear Maintainer,

after update from 1:16.16.1~dfsg-1+deb11u1 to 1:16.28.0~dfsg-0+deb11u1
asterisk segfaults trying to place a call:

asterisk console:
    -- Executing [<EXTN>@localpeers:1] ExecIf("PJSIP/client-00000000", "1?Dial(Local/<EXTEN>@go-local)") in new stack
    -- Call accepted by IP:4569 (format g722)
coupler*CLI>
Disconnected from Asterisk server

dmesg:
segfault at 920 ip 0000560961edcbd0 sp 00007fc3379aa4d8 error 4 in asterisk[560961e66000+1cf000]


I can send the dumped core.zst (3.2M) personally.


-- System Information:
Debian Release: 11.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable'), (400, 'proposed-updates')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-19-amd64 (SMP w/2 CPU threads)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages asterisk depends on:
ii  adduser                  3.118
ii  asterisk-config          1:16.28.0~dfsg-0+deb11u1
ii  asterisk-core-sounds-en  1.6.1-1
ii  asterisk-modules         1:16.28.0~dfsg-0+deb11u1
ii  libc6                    2.31-13+deb11u5
ii  libcap2                  1:2.44-1
ii  libcrypt1                1:4.4.18-4
ii  libedit2                 3.1-20191231-2+b1
ii  libjansson4              2.13.1-1.1
ii  libpopt0                 1.18-2
ii  libsqlite3-0             3.34.1-3
ii  libssl1.1                1.1.1n-0+deb11u3
ii  libsystemd0              247.3-7+deb11u1
ii  liburiparser1            0.9.4+dfsg-1+deb11u1
ii  libuuid1                 2.36.1-8+deb11u1
ii  libxml2                  2.9.10+dfsg-6.7+deb11u3
ii  libxslt1.1               1.1.34-4+deb11u1
ii  lsb-base                 11.1.0

Versions of packages asterisk recommends:
pn  asterisk-moh-opsound-gsm                         <none>
pn  asterisk-voicemail | asterisk-voicemail-storage  <none>
pn  sox                                              <none>

Versions of packages asterisk suggests:
pn  asterisk-dahdi   <none>
pn  asterisk-dev     <none>
ii  asterisk-doc     1:16.28.0~dfsg-0+deb11u1
pn  asterisk-ooh323  <none>
ii  asterisk-opus    13.7+20171009-2
pn  asterisk-vpb     <none>



More information about the Pkg-voip-maintainers mailing list