-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 22 Jun 2023 14:47:22 +0200 Source: asterisk Binary: asterisk asterisk-dahdi asterisk-dahdi-dbgsym asterisk-dbgsym asterisk-mobile asterisk-mobile-dbgsym asterisk-modules asterisk-modules-dbgsym asterisk-mp3 asterisk-mp3-dbgsym asterisk-mysql asterisk-mysql-dbgsym asterisk-ooh323 asterisk-ooh323-dbgsym asterisk-tests asterisk-tests-dbgsym asterisk-voicemail asterisk-voicemail-dbgsym asterisk-voicemail-imapstorage asterisk-voicemail-imapstorage-dbgsym asterisk-voicemail-odbcstorage asterisk-voicemail-odbcstorage-dbgsym asterisk-vpb asterisk-vpb-dbgsym Architecture: i386 Version: 1:16.28.0~dfsg-0+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Markus Koschany Description: asterisk - Open Source Private Branch Exchange (PBX) asterisk-dahdi - DAHDI devices support for the Asterisk PBX asterisk-mobile - Bluetooth phone support for the Asterisk PBX asterisk-modules - loadable modules for the Asterisk PBX asterisk-mp3 - MP3 playback support for the Asterisk PBX asterisk-mysql - MySQL database protocol support for the Asterisk PBX asterisk-ooh323 - H.323 protocol support for the Asterisk PBX - ooH323c asterisk-tests - internal test modules of the Asterisk PBX asterisk-voicemail - simple voicemail support for the Asterisk PBX asterisk-voicemail-imapstorage - IMAP voicemail storage support for the Asterisk PBX asterisk-voicemail-odbcstorage - ODBC voicemail storage support for the Asterisk PBX asterisk-vpb - VoiceTronix devices support for the Asterisk PBX Changes: asterisk (1:16.28.0~dfsg-0+deb11u3) bullseye-security; urgency=high . * Non-maintainer upload. * Fix CVE-2023-27585: A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead. Checksums-Sha1: 65fe40633b7409a8de62396abf86b61d7c065282 584892 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb fa319e8b25fa898b3074b16f74a0df71d17c23ab 1593000 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_i386.deb 87597379e853a6158f05471b3dc492e42e9a3ba8 5603672 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb a8c3563c9d76bea0f36271e3a0295bccec29d48d 81340 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb f23e92baf37f7dd37e3f6565a3de1e3bdc715e8f 1376272 asterisk-mobile_16.28.0~dfsg-0+deb11u3_i386.deb ff8924156930e6ed0f9c6652e97248f80cff111a 9147084 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 62bc3e02e8460c2636183867aba54e6eb5bb503f 4031452 asterisk-modules_16.28.0~dfsg-0+deb11u3_i386.deb 99136294c8277174a8a0007014845e0e72549890 47012 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 838dbc53f40145d4f205bba30bcb135e2ff57276 1359508 asterisk-mp3_16.28.0~dfsg-0+deb11u3_i386.deb ff377e08f4c8cabd75780eb9eee7f4b8637079e0 124136 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 40e6088d8069cfca1009163122a38623b2089f01 1375884 asterisk-mysql_16.28.0~dfsg-0+deb11u3_i386.deb 5785b88ea101eb24086276301e041149a0c74cbc 1223284 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 66fdc5437ce3405742ad633cc63b88d839231d0e 1711344 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_i386.deb fe1ae4415dcf2a118d04683014488498c9949862 1156600 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 5c4a62f65eed110ab7104176a09000a8a0fdedbb 1781768 asterisk-tests_16.28.0~dfsg-0+deb11u3_i386.deb 3d61c372c4ca9214961c2a97408ccc59dab0946e 238696 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb e7d851e1e2154154414d854bd3915ad42218c23d 282176 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 9803a818967588b82f86823a556455e26b6014ca 1453964 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_i386.deb 71c94491de90041d62de534c1c25ff8df9792fef 249604 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb a2fc5eedd1804731516262fed6392959a645cb2c 1442276 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_i386.deb 1949d7329975e98e65c89040797d2fb96172cfdc 1436404 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_i386.deb f2d1233a5e2a126bc21aeaf5313707c723bf01f0 65172 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb f0bbc20e30f02023a7e771e266b03a32e91f5fcb 1364976 asterisk-vpb_16.28.0~dfsg-0+deb11u3_i386.deb 6549904e7f14b14aa2d3f542aaca3a02185ad9bd 27569 asterisk_16.28.0~dfsg-0+deb11u3_i386-buildd.buildinfo 4c61f90fc2619be35fc730b5987100ba550da259 2478124 asterisk_16.28.0~dfsg-0+deb11u3_i386.deb Checksums-Sha256: b14ecf67a8a1a9a8d44d77d7c28482fb28edc5f5f350d18475b80a0998c5fd67 584892 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb d0d9487dfeefb4c6018c4f805607714de459b9b3136a45a489daf576d4f4ce40 1593000 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_i386.deb 9ea7fabcfd761e7c6126be8f04eec2e4b5482ffb9a8d7a8006c71776c189fefc 5603672 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 2bbb60415b08b5e3e02b4166f27bded2c4ec859f93f4cb193f2f262eab49bc48 81340 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 23c3a27bb19597ee15d333180f6f316b3ebaecd62e3a3b0e40977df960aef535 1376272 asterisk-mobile_16.28.0~dfsg-0+deb11u3_i386.deb 03e3755acea286e5e40f31b0c2c93705e7e064f9c7ec464a163bf190a18c744e 9147084 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 8b50694c473ee6c8380c2069de7963968711007bf3836aea600f21f2efcf09e3 4031452 asterisk-modules_16.28.0~dfsg-0+deb11u3_i386.deb d3c182d26d8b172ad115631bd62847fffa1606acc9bd34ff6e1098000d2d5fbd 47012 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 21ec3d35b4ab2f042ef7a52c5a43830a0f35e858ed1c2eed9f92232f0d438037 1359508 asterisk-mp3_16.28.0~dfsg-0+deb11u3_i386.deb d58e4b3a3c150bd0aa7033668fba2a0e9c71722153742d3f8af1e7b17a485fdc 124136 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb df8b4ce1c3483624cdcfbcc2bfe73433428ae92de2871ea4bb4e63b4d591b8c0 1375884 asterisk-mysql_16.28.0~dfsg-0+deb11u3_i386.deb 35af67c8f83d108f4eca815a2db3e4dc43bc2312e60ecffcf05201f00e5b7093 1223284 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb b0e4e06629909bfc1798384ba4f1c225e04f36f5cd5da61d14c5ee0abf7bbe62 1711344 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_i386.deb f83f6042b2607bff8c1193199ef0dc7d303f22bb7750b44ac1f1e9a08bc922a7 1156600 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb f78a81e04adb8cb8c802c53e5b7be486542e30bed52c5bb124486a282bcb14cc 1781768 asterisk-tests_16.28.0~dfsg-0+deb11u3_i386.deb 75098f1cbd1a0623f5a11ff2401094c8cde36f949887adece2777fac711d9d49 238696 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 5317b634a3d3e52749281427ba01a77d7842bac392a943297cdb292b3d277329 282176 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 06987a4252b8814ad5ff675a39adec44ecd530d1f22edca6a8ca628a9adf69df 1453964 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_i386.deb b74c89445c4f2c87fd5706d6bba22418993a2361bae53fa70a9b177d1c67281f 249604 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 0d446a764fba600f342f7dddd8324dd33c24463cb0d40508adb64c8fe7af753e 1442276 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_i386.deb 3b00ca555a6ff3509914f965a2c90f56ab544ad7f4f7711739dd5eea5ec500db 1436404 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_i386.deb 50f37453f090849eb7caf25b644ebf4c88c4eccf6317490030af90300dc0762c 65172 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 96149b1a84b93c8d3b2e39b092205b69cbb21c8c022463b7987886e21d7d05fb 1364976 asterisk-vpb_16.28.0~dfsg-0+deb11u3_i386.deb c2850edb4d272c71b8e05f4f5374de189a5069a71848f5f9fcb243488ba66256 27569 asterisk_16.28.0~dfsg-0+deb11u3_i386-buildd.buildinfo 675568a83613b2bd48ae3ab2c9e8ef18376e6ac30470b3aa47c0d17fea4988cb 2478124 asterisk_16.28.0~dfsg-0+deb11u3_i386.deb Files: 534dd4a3e86332851163205eb4e43a99 584892 debug optional asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 97bcf1e10d8afeb9cb58a67b0e701676 1593000 comm optional asterisk-dahdi_16.28.0~dfsg-0+deb11u3_i386.deb 1e23721c1034784d5f46f9041b57f08b 5603672 debug optional asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb a0f31dcfb7b47e2dd65e27f6c68b5d0f 81340 debug optional asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 023d9409aa57e50ab219bac847776a75 1376272 comm optional asterisk-mobile_16.28.0~dfsg-0+deb11u3_i386.deb c735578ceac9d9bce3ca3da36f560775 9147084 debug optional asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 45802ce0f623549a6fcb210a79e0ecdd 4031452 libs optional asterisk-modules_16.28.0~dfsg-0+deb11u3_i386.deb d35b9f5ad0df317eee265e36bdebbad7 47012 debug optional asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 1bb283479d86be279a9d766dc07e9352 1359508 comm optional asterisk-mp3_16.28.0~dfsg-0+deb11u3_i386.deb d87afaf78df29111bff155de9f51e973 124136 debug optional asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 4e063ae9e14cf96ae4e266db5f8aaaf9 1375884 comm optional asterisk-mysql_16.28.0~dfsg-0+deb11u3_i386.deb 766c8b2acbfa0df3fcf2c510c9695ac2 1223284 debug optional asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 900e914f6f1b6bde3e1c76cd82b82649 1711344 comm optional asterisk-ooh323_16.28.0~dfsg-0+deb11u3_i386.deb e01c99448187921427c644e86a1396b5 1156600 debug optional asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 3c53366a5a8242619169cb5f9f52e633 1781768 comm optional asterisk-tests_16.28.0~dfsg-0+deb11u3_i386.deb ae8d8240b3d8b377735faab1e0ca7d7c 238696 debug optional asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb c8e37f55ead3f5c3c5dea9b9231aeed5 282176 debug optional asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 6f64f54bb6415013cc38b869c65ce828 1453964 comm optional asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_i386.deb 0bcc7c78f82504b48538b01748ead761 249604 debug optional asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb a84244033d9b4c8d33d944eb569f5d7a 1442276 comm optional asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_i386.deb 6d882eb3070656d3bb477afccb919d48 1436404 comm optional asterisk-voicemail_16.28.0~dfsg-0+deb11u3_i386.deb 44ffddb1609a92f890c5eba94fd1804b 65172 debug optional asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_i386.deb 83305af82131a36372dc660db6b0e7f6 1364976 comm optional asterisk-vpb_16.28.0~dfsg-0+deb11u3_i386.deb 526120cbaa10932bbfd06a3d1af88602 27569 comm optional asterisk_16.28.0~dfsg-0+deb11u3_i386-buildd.buildinfo 7f42501e6ff56615a7a9af610759eb24 2478124 comm optional asterisk_16.28.0~dfsg-0+deb11u3_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7bJOCbihllHz5a8G6bGbnoZY/NwFAmSUWN0ACgkQ6bGbnoZY /NxLLxAAk8L/7IlyTDQKBON9FFk+VWPwu/Zu9gPAvuD8WdaNHSx48OVEKp3zHX2f qvKp8nwT2Oqgf8ML8+nmteTcLpYmuVlyImMH5/uDfywATJYxBJJfY28uxcskwKHd Ev21xLwwpZ/Ny7GyOGx9AlUUB7fwmPrPbdwWXmDa+fcD+P6TzUVag9Ghjv9kIQAT +50jMTARHVYqwv+jcJF3C6ac/mKr+LHx9RX8/d7Tq+QP2wdCaNnllmTBHay46NTT 8JEnnYxEc81xjXzh3VhQNwVRpqVr6SGmfSBdqHvKMUaXwHLizp/1vdBeis9aM1OI G/+XmZdD5CRAFYaNUSgAudAjNkgPp1d8r4LE9+XkpOpPGgq5s6U5KLHmZhssMU2O htyDaMjo3N6FFvH2gtPp5dTVui6WolDF4WHgkDkOF9yhmaYGBLbqDmcmk+v3CwTI 81kbrlLUr+roOLWJfe9sQRhFSC0sTMoc1dfn5jbqkeooevJzVaMxuE6Ai4Jq8Mbi L/Z3sZ/crM8LRXKdBm8Z2uXXeNT/NGDofX89htmhzv8XUqBfHLfFbIC8P47LQZSU y6qzOs9oIGTpQ56mkPqaDY0I6EEKEG/Ti2xaVEkjRtlBNGsBsiu9qV5lnBCc8lB8 q4DMXaAf/GQY61vYOakm+XB9CTTpIStbeY7YUItDhC+Z5tAQpdo= =i/gV -----END PGP SIGNATURE-----