-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 22 Jun 2023 14:47:22 +0200 Source: asterisk Binary: asterisk asterisk-dahdi asterisk-dahdi-dbgsym asterisk-dbgsym asterisk-mobile asterisk-mobile-dbgsym asterisk-modules asterisk-modules-dbgsym asterisk-mp3 asterisk-mp3-dbgsym asterisk-mysql asterisk-mysql-dbgsym asterisk-ooh323 asterisk-ooh323-dbgsym asterisk-tests asterisk-tests-dbgsym asterisk-voicemail asterisk-voicemail-dbgsym asterisk-voicemail-imapstorage asterisk-voicemail-imapstorage-dbgsym asterisk-voicemail-odbcstorage asterisk-voicemail-odbcstorage-dbgsym asterisk-vpb asterisk-vpb-dbgsym Architecture: amd64 Version: 1:16.28.0~dfsg-0+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Markus Koschany Description: asterisk - Open Source Private Branch Exchange (PBX) asterisk-dahdi - DAHDI devices support for the Asterisk PBX asterisk-mobile - Bluetooth phone support for the Asterisk PBX asterisk-modules - loadable modules for the Asterisk PBX asterisk-mp3 - MP3 playback support for the Asterisk PBX asterisk-mysql - MySQL database protocol support for the Asterisk PBX asterisk-ooh323 - H.323 protocol support for the Asterisk PBX - ooH323c asterisk-tests - internal test modules of the Asterisk PBX asterisk-voicemail - simple voicemail support for the Asterisk PBX asterisk-voicemail-imapstorage - IMAP voicemail storage support for the Asterisk PBX asterisk-voicemail-odbcstorage - ODBC voicemail storage support for the Asterisk PBX asterisk-vpb - VoiceTronix devices support for the Asterisk PBX Changes: asterisk (1:16.28.0~dfsg-0+deb11u3) bullseye-security; urgency=high . * Non-maintainer upload. * Fix CVE-2023-27585: A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead. Checksums-Sha1: bc86f3f78ac4acc6e6b319a7cbfaa9ae025a35d5 666136 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb e9d0c6a3570035f74d566b95c8557a7f80351a7a 1588324 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_amd64.deb b24da5337aedb9413c53d730aeef17681ed8d915 6492476 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 56af825478192c9e2d4e425c66c87ca894b84af1 91520 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb fac695996eb77211f35fbe4d3aae954fa849b5b5 1374840 asterisk-mobile_16.28.0~dfsg-0+deb11u3_amd64.deb d0eb9de8fbc0867d3e0f96e315cf7d95970b73a0 10289352 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 12d7174e4be25ebf32a9ef67630c4acaa2c60d8a 4000304 asterisk-modules_16.28.0~dfsg-0+deb11u3_amd64.deb bbf5e6dc7e356fc526df7dd1d1d4f0c5fed0afb0 51772 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 3bba2fa80dc61f69f4d3171dff8dfca670b410e0 1360184 asterisk-mp3_16.28.0~dfsg-0+deb11u3_amd64.deb d90c1b7a17605b73ff19331c46ffa73e06a5129e 136020 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 63ea17f554b62b219f954196c30185e344f1155d 1375720 asterisk-mysql_16.28.0~dfsg-0+deb11u3_amd64.deb 709e95d976df47b012737f532e30a247a56a5ff4 1520360 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb d6aed59cc62d69fe469bf3a292e7cbc6eeb59d80 1676164 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_amd64.deb 7b3dac681b0c8beef911de75e1a71f573581b2d7 1359304 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 424d7e6cf870fe7f38720245a4a0f770ca49dc3b 1803592 asterisk-tests_16.28.0~dfsg-0+deb11u3_amd64.deb 3f3be7c82fa2b5c95f32a3fa3ea6fe42b7d3e7fd 275656 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb c314097123d1c3f531f0bf5968c5182a4b0bece3 326740 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb b6224bfee7ef9c53fc4620d0b75962eecb0a1027 1454644 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_amd64.deb a0409ef7ea7a2c8818a864c76ce98ca93ff03acc 289452 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb d2f568e82dd18bc1dd93058847d150e97e507b4d 1442044 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_amd64.deb 588efaeb8ef23e36886a757effcf11e82677fe2a 1436512 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_amd64.deb c3b13e0ffed4943aac1751520f86dd8f03bc6ecf 71000 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 0547f2af82385b7eefdc27953fd1b0e94a20c52a 1364148 asterisk-vpb_16.28.0~dfsg-0+deb11u3_amd64.deb 39122dbb8fe1c87960f6c499b400f27330462e15 27715 asterisk_16.28.0~dfsg-0+deb11u3_amd64-buildd.buildinfo 42fc8f87dc317994d95fa26374fc67ca6379498b 2399280 asterisk_16.28.0~dfsg-0+deb11u3_amd64.deb Checksums-Sha256: 28f352ce1b660f2e5b3d6ede9f103be9941c767450bde86db7fb765dece2fcff 666136 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 9b8b14215bf3ab9b3d6e11f703b3e2419b6abe29d991ef93973f4a0524c2ab50 1588324 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_amd64.deb e0bf5325496c66413b788ad49250fbb7df1718f892679e6eb6517a527f0c3c4a 6492476 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 11bedaccb4e262079a35f7fa555c1d7f86c2cc4b521420de1a991495e4fd8fbe 91520 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb fef1d5d2cda403b9a3f92c86f95eea95b78e01af4b26572c3d66c96ae23a79e8 1374840 asterisk-mobile_16.28.0~dfsg-0+deb11u3_amd64.deb ffe5dbab47d6ad56f276de3d1e5b8c895c77ab136fe28beb5dd1c37037440dd4 10289352 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb e165e4427791b81a23c6ae21cebe3cd0e74e7bf652f41180bbc7e463a5bad1ed 4000304 asterisk-modules_16.28.0~dfsg-0+deb11u3_amd64.deb 0e9d7b9a4f4e941653d4a356748868111baeb32942932772e80c5fe1489e701d 51772 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 1e01ed0d3fe4e526ddc50fed06aebc1871ae4ab98d4a34e5ae3b33d5308730d1 1360184 asterisk-mp3_16.28.0~dfsg-0+deb11u3_amd64.deb 63d579fefb22afe6ae22d5a370f400eb486125bc06f6ae98c2ae30a6a89bf468 136020 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 003939839763b31e89cfd062a27d365a557cabedb8059c081209a61cce0a72f1 1375720 asterisk-mysql_16.28.0~dfsg-0+deb11u3_amd64.deb 25178ceaf2c61104d37daadfa4cde36a4cdf9ec5c3d1474bb87c177353f54c0a 1520360 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 46709488f3e03d8a79c85bde46c64d0a8c96b6cc1e3dd34696124e3352e1ab3a 1676164 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_amd64.deb 125c2f9d7c4a0bf90390885026f733fc1d6504b164248c4ca0b1395d20aa8111 1359304 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb e1360482704a26fe57f742de5461be2709b2c7a06d104d35dc52f27edcde2319 1803592 asterisk-tests_16.28.0~dfsg-0+deb11u3_amd64.deb a52ea1483f85e89139ace922bf3b5bfe23b51111b6a9518fe2885b91a7eb0855 275656 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb b205921da0ab7789cc6019215fef6d6ddb8d20d2f6186be81d53ef083cf9d85e 326740 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 4890c55c84ce634feeaaa78cf2c648aebd8be8b19f668fc8e9fcf2845916a4d8 1454644 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_amd64.deb de9d0767e3fe6f25ac3d16224e51020b6b1f8842f92b40014e395703d089929b 289452 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb e0b02f9282299bcffef0afb8452877e5d6437d1f777feac4a51be3b562cd24f1 1442044 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_amd64.deb 3119508dab26a41fe1cef9e76f4313e946b1bbbf8ed75eb0292a625e32b88405 1436512 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_amd64.deb 06647a989942c7fe94a69efa80403eef5f80114d018608adac313c06b2c9d6cc 71000 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb f3c0bcd4aac3f35c348aa20cfe582825b23c482724a7c4c7abfd513d3a24290e 1364148 asterisk-vpb_16.28.0~dfsg-0+deb11u3_amd64.deb a17a9aaf4dbde4745a2b3a1b1ab1d7ccc22593e395dbce897a31cbef7750b3e2 27715 asterisk_16.28.0~dfsg-0+deb11u3_amd64-buildd.buildinfo 33403d60175184aa1223c0b82fca5a9eb07c70cee9ea4054c0542778505b264f 2399280 asterisk_16.28.0~dfsg-0+deb11u3_amd64.deb Files: 8a257420e46a783fec762af86ef84c1c 666136 debug optional asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb c454d3a6adfb0372a56d5e93126ad472 1588324 comm optional asterisk-dahdi_16.28.0~dfsg-0+deb11u3_amd64.deb 5daf64269d21e8e799099381eab5a0d5 6492476 debug optional asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 9349883b14a763cb17fdb89aaf4e59eb 91520 debug optional asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb d4546ade5253a1bf768791f05bef2a34 1374840 comm optional asterisk-mobile_16.28.0~dfsg-0+deb11u3_amd64.deb dbb0a5e7ff975d8458bfdddf5aa4aae2 10289352 debug optional asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb f850ffcf3f640c54b9531420506c0295 4000304 libs optional asterisk-modules_16.28.0~dfsg-0+deb11u3_amd64.deb 256052f2cceed127f3bd2f0d71e9c0ff 51772 debug optional asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 3d3a937e589d1eb05b973097861a294c 1360184 comm optional asterisk-mp3_16.28.0~dfsg-0+deb11u3_amd64.deb 08bfe1a2ef6e390e5c172f08e64a8b12 136020 debug optional asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb ce81239db784be65d4ddeb2c32238ed7 1375720 comm optional asterisk-mysql_16.28.0~dfsg-0+deb11u3_amd64.deb 562c0cefbd1b57dd48a0a0fa7924960d 1520360 debug optional asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 40ed4833917522c66b93c41959afedeb 1676164 comm optional asterisk-ooh323_16.28.0~dfsg-0+deb11u3_amd64.deb 3a25f231615f2ea38a057b32397303af 1359304 debug optional asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb d7788df72157c234bdafc402c971c648 1803592 comm optional asterisk-tests_16.28.0~dfsg-0+deb11u3_amd64.deb 9cb21b28b99c8797a2c2019aaa33893e 275656 debug optional asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb f601e9db9f8b522fce1e14ad216fecf4 326740 debug optional asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb 32a316eb7131d81013ccca5aac042f08 1454644 comm optional asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_amd64.deb b92e38dd184b366e21b67d1a9303729c 289452 debug optional asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb ddfde52fcfee130e2f0b9cdd4ddf616b 1442044 comm optional asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_amd64.deb e1a23992971e137eb7cf61d813b5450a 1436512 comm optional asterisk-voicemail_16.28.0~dfsg-0+deb11u3_amd64.deb 49b88c9d5f8a14337284ab84cdb4464d 71000 debug optional asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_amd64.deb a9d9400ec99dc55daa43f539d165f392 1364148 comm optional asterisk-vpb_16.28.0~dfsg-0+deb11u3_amd64.deb c6ae3dc074c2d0ca4b7fcf8fffe15ef2 27715 comm optional asterisk_16.28.0~dfsg-0+deb11u3_amd64-buildd.buildinfo 6e5d3458987c992c34984e792a4daa98 2399280 comm optional asterisk_16.28.0~dfsg-0+deb11u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEi/TVpVg0yb7dq8QfDZWW6X29YdoFAmSUWQYACgkQDZWW6X29 YdqS7w//bREOS1t/H2Hmr2LEA2JAD0HgZcTuivFVG3OZgAvAkWEglCYEV2tdsZ2p k7tm8p+8PMG/qJlkoTO12ob7WKCF5C1JA19QVbd1uHn6yXLoQ56AALsifvDvfgbe 1IUar0RISGzNaIu/EjyMz2CSV7lf/wx2ueAb4QqLy+ExVq+T330q4tCRkDwhZsCZ HulsEOodPgCkTBQfszgs5vTWhalACYCfv9ObcnCvsfR0dWFDt+B+79KMPN9nehO3 xwZMlGFK9rbE7iHS4IokVreAR2EomXh1sqQ41/dOWHFSNdrhmJrueWgNnbBZqGH5 v8tsyWfessI30OPxM/uYvDhPDj8fOK/bZruC6AWBe7R7UApFX/W/7zDoC2j3kGap 14rL8tqnFXqNAPKt9iXu9FZKm94mjhI0WgRlf4tf6hbrFhCXv8Fs3gA/cWVRJpt2 LMTNNWQLRqu8KpXb4RXJJqlY5Lgp7AR3ycbZJ9SXwMiXL+h5/UqcDYKRVO4AdRb8 V8P8mWPlh1yaw+jTlNRnR/S4CXBpnKq3yPOfy4q8L3GoS8hGCxUihZJVXPIrlv/n cte0wTUxuUKPC6TWn/WSDm1Y1QcQ6Kmw3ZsOaX7hzohn4PkCAXKVc4PABzqV6VgZ 7OYnyeDlz9+92FpRmA4QxsE8ffV3kZFZCq/BWuqcCS28ff9e7X4= =4Wvu -----END PGP SIGNATURE-----