-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 22 Jun 2023 14:47:22 +0200 Source: asterisk Binary: asterisk asterisk-dahdi asterisk-dahdi-dbgsym asterisk-dbgsym asterisk-mobile asterisk-mobile-dbgsym asterisk-modules asterisk-modules-dbgsym asterisk-mp3 asterisk-mp3-dbgsym asterisk-mysql asterisk-mysql-dbgsym asterisk-ooh323 asterisk-ooh323-dbgsym asterisk-tests asterisk-tests-dbgsym asterisk-voicemail asterisk-voicemail-dbgsym asterisk-voicemail-imapstorage asterisk-voicemail-imapstorage-dbgsym asterisk-voicemail-odbcstorage asterisk-voicemail-odbcstorage-dbgsym asterisk-vpb asterisk-vpb-dbgsym Architecture: mipsel Version: 1:16.28.0~dfsg-0+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Markus Koschany Description: asterisk - Open Source Private Branch Exchange (PBX) asterisk-dahdi - DAHDI devices support for the Asterisk PBX asterisk-mobile - Bluetooth phone support for the Asterisk PBX asterisk-modules - loadable modules for the Asterisk PBX asterisk-mp3 - MP3 playback support for the Asterisk PBX asterisk-mysql - MySQL database protocol support for the Asterisk PBX asterisk-ooh323 - H.323 protocol support for the Asterisk PBX - ooH323c asterisk-tests - internal test modules of the Asterisk PBX asterisk-voicemail - simple voicemail support for the Asterisk PBX asterisk-voicemail-imapstorage - IMAP voicemail storage support for the Asterisk PBX asterisk-voicemail-odbcstorage - ODBC voicemail storage support for the Asterisk PBX asterisk-vpb - VoiceTronix devices support for the Asterisk PBX Changes: asterisk (1:16.28.0~dfsg-0+deb11u3) bullseye-security; urgency=high . * Non-maintainer upload. * Fix CVE-2023-27585: A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead. Checksums-Sha1: cd488811aa10fcb5a4199995da06b05bab3920bc 649696 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 00149377ece5c42b57db92063fb8056ab6da6c9c 1548832 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_mipsel.deb 37d3a25b536cc88ae66bfb9bd6f121d9cb3c9627 6453052 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 8ca6aa3f7cfcce6f6fb9a6a5670208ec707fa944 87172 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 32b630c56d98f2660f611dc330f44b93476c63be 1368768 asterisk-mobile_16.28.0~dfsg-0+deb11u3_mipsel.deb 9bafd0428d926b30e64c3002ed5920fbd3d3795f 10076188 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 94e4abc3d6bc4951147377a3e8d36600a74f6d0f 3639036 asterisk-modules_16.28.0~dfsg-0+deb11u3_mipsel.deb 25346b96772ddeee2cf6c7dbe92d33193afcdaa7 52092 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 60e8718d2c77ba286ea5c53dd83b81755232e97a 1361332 asterisk-mp3_16.28.0~dfsg-0+deb11u3_mipsel.deb 49ace9b9414d6679d287c444510c771bfc47eead 132724 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 4820889a085df5ee7dc777745d2933bf8348991d 1370532 asterisk-mysql_16.28.0~dfsg-0+deb11u3_mipsel.deb 8ecbdd54633449115b3345bc99b0fcf257ec02fe 1477896 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 67410c3d2f534818a63d755a88a3603a8c2ea172 1591164 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_mipsel.deb af1a6f9a6fb4b562862943be632df2669c4b3e63 1380352 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 44de3e28724688be9bbe2708bbe4d41001d81d64 1713020 asterisk-tests_16.28.0~dfsg-0+deb11u3_mipsel.deb 4cbbe0e3c05d5aa1ebc2fb45fa92c8231eaf30fb 274324 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb c255861c9fd0d50889a1c96132072e39f567eb5b 323312 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 4452faa7c6d0a28f328fb2a7d99cee8014245e56 1440012 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_mipsel.deb c7ef69a45fc0637da9b394a4dbf74694d16b4c7e 289008 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb a50deb92ebc9069ea1d8de7b304e9dbfb97092e2 1428888 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_mipsel.deb c14ba5c28bd720bdaa76ff2c8514c505cf6b5563 1424524 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_mipsel.deb 97a187fd1e32ba1218d043795b57ade03ac58245 67940 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 158bd795cc3b1c030b4a106fe13d0c26512cfdda 1362116 asterisk-vpb_16.28.0~dfsg-0+deb11u3_mipsel.deb c4d9d646821229d509435f9906b7d79e994344a2 27391 asterisk_16.28.0~dfsg-0+deb11u3_mipsel-buildd.buildinfo 6d1f970aca32e21469e778977a1f506c03357dba 2148540 asterisk_16.28.0~dfsg-0+deb11u3_mipsel.deb Checksums-Sha256: 783b1902cd892ff2b72ccbb231f17304c0e66f97bd2810eec8227428bf1bc0f1 649696 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 653aab0ec0e14d966e9254de59cc610854c2fc768e334f5f4a627106c93ef4ba 1548832 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_mipsel.deb f61df475b785a6f9cb85969ee14380b1f820f2fddaf4845486ad5e9f9bed7e55 6453052 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb cf7a36ed611c4500d58bd06773a30af89c3b3c5b731771fde1ce7ee5b5755960 87172 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb d8cf2a21a9534a05dc3f881c85140ea2621a2bb0a4e7d0a5ca0f0e232ff08b6b 1368768 asterisk-mobile_16.28.0~dfsg-0+deb11u3_mipsel.deb 84ee0c1b7bd9c9f26ab52add4008fa78691a0c827b57e1eeb87302b3e4c0f4bf 10076188 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 571030dad49b0f70bece273dbc146474a8ce8e1620c47732d969863d78d2cd2d 3639036 asterisk-modules_16.28.0~dfsg-0+deb11u3_mipsel.deb 3f87efad607ffe22cd197c671fe7ca480eb8a97c268b83e75254f7c8a21a9831 52092 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb a27e1f6e2120c29088cc53db040da3d0a3bea8f6372010f94b6c796da8e10f11 1361332 asterisk-mp3_16.28.0~dfsg-0+deb11u3_mipsel.deb 2e66dd9889958861cda4d868074a7e338979eca9395384a8be52b17372e4cf9f 132724 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb e8f29fa5a3fe55ddc07166b5b9d60823ac856de73e439ab1b83f942567854cd2 1370532 asterisk-mysql_16.28.0~dfsg-0+deb11u3_mipsel.deb ff022cc96caeafb9f15414dfbef03c304379c76185f8c8d0fd1b2167976d2b96 1477896 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb d9883ae5bad211f11d056fc228cc093448da9824f22ba78418c1561de3708153 1591164 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_mipsel.deb 5abff98537cc1840d8c94d4cd1648b03d82b8f1923a9539e831d33214e06f5b6 1380352 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 77a084c1109385a5ef5a50bf4aa38a16ab8da4dc67e754f7b76a58795bfdbbb5 1713020 asterisk-tests_16.28.0~dfsg-0+deb11u3_mipsel.deb 92e3c891afedac76ff6da45cdc3c5fe018de9ae9cda6d777e486e05501dc0595 274324 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 0b02aa881560b4140f0c3bc79e773494ef44ae4fceff6ba4d799005eb7e23f48 323312 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb a8c0e9cf8620d75c95b4f50b87d45357049a7c343876f846da50abb63424d8a4 1440012 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_mipsel.deb 9ad94e25562d15edc8531d94faee22b22eb407586cd87a0af55ff92eb272fa7c 289008 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 3c6e07ca3415ef26dece114b1ddf132d7dc438a74d1901cc95981f35d9841358 1428888 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_mipsel.deb ad1292edf3f5ffc0faec7ce170c8b51b330ce82539ae3fb5085baaa43d08dbc2 1424524 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_mipsel.deb a6fa2fb353498993fa775e605477f4cc319b7a273a028ff3e08a5e1920341fc0 67940 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 1b4925f295a9a3c0c3cc4e12ac050339e771f8e4689319132123aab829926c3c 1362116 asterisk-vpb_16.28.0~dfsg-0+deb11u3_mipsel.deb 8c45bc3e916c3d787c5e96bf2860339edc3656a6d7fb6fe7d557fba259bde2f7 27391 asterisk_16.28.0~dfsg-0+deb11u3_mipsel-buildd.buildinfo 752b91371e48ef3a9828c9e944735ed00ed94d6102c173c97bbce6253914f4ec 2148540 asterisk_16.28.0~dfsg-0+deb11u3_mipsel.deb Files: de9fd7a9d33931262aa9d6307d933337 649696 debug optional asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb f413098b1e05f3042c72957f9edce59b 1548832 comm optional asterisk-dahdi_16.28.0~dfsg-0+deb11u3_mipsel.deb 645d8c6d68e945e53840804b4a404ab8 6453052 debug optional asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb fbc7b25660f3b5ee5fd08b49a62950cf 87172 debug optional asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 8750585c7ed6874445ba4ad82d07c1c3 1368768 comm optional asterisk-mobile_16.28.0~dfsg-0+deb11u3_mipsel.deb ddf91833f268c73522cb92170a3821a0 10076188 debug optional asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 55340c88b597d0301d8fe05d740b9f67 3639036 libs optional asterisk-modules_16.28.0~dfsg-0+deb11u3_mipsel.deb 7128f48e027d9734316623dc6b1b8519 52092 debug optional asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb c50237473128de516632427ec38ccd24 1361332 comm optional asterisk-mp3_16.28.0~dfsg-0+deb11u3_mipsel.deb 94014c768bf1c0d4590d96b0afde041f 132724 debug optional asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 17f3507432e00417a9062acc5abb159c 1370532 comm optional asterisk-mysql_16.28.0~dfsg-0+deb11u3_mipsel.deb 448b51e6f713e93d86b9e2cad6504690 1477896 debug optional asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 41e22d154f6d515b58b87a5d4ec8f220 1591164 comm optional asterisk-ooh323_16.28.0~dfsg-0+deb11u3_mipsel.deb 5050596b05860d9b04ca06680f489209 1380352 debug optional asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 93a586d7cf037917b83c97047f88993c 1713020 comm optional asterisk-tests_16.28.0~dfsg-0+deb11u3_mipsel.deb 6e016e58330d75b8a70ed80b6446ad95 274324 debug optional asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 784c9bd98bed8a9e44dc4df48c97ad50 323312 debug optional asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb be94cd4362ea7b30962b48b4679a31e9 1440012 comm optional asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_mipsel.deb f0c0bcb69c228cfc2b5746f2ed6a2239 289008 debug optional asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb 7e1fd58d264a01069036dc46d1b89559 1428888 comm optional asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_mipsel.deb bf8a01c38b77bf41f4719f2b61c3e911 1424524 comm optional asterisk-voicemail_16.28.0~dfsg-0+deb11u3_mipsel.deb b2657e79dfcb939fc340dc0d611229aa 67940 debug optional asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_mipsel.deb db7175d870d9e4916b6bbb8cc51625c1 1362116 comm optional asterisk-vpb_16.28.0~dfsg-0+deb11u3_mipsel.deb e97affee6b54c479c02d63632bf1e32d 27391 comm optional asterisk_16.28.0~dfsg-0+deb11u3_mipsel-buildd.buildinfo 2fb81edbcb032ce6dc4c8f9057ca25db 2148540 comm optional asterisk_16.28.0~dfsg-0+deb11u3_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7FUbSrfgk+qhJhySoQbzkdO+xGgFAmSUaY4ACgkQoQbzkdO+ xGiwuw/+KAl+1aBSdDcK0nJoc24uJAw+HovQZZjt1OdSgYCkuW0PZF+PBvW2OrWJ F2+hG5kDmCNW1Wyj6S169viZXStMe0nUbZ/CjQ2aFfJzQLJYxnEAF9/lSkjtjJYN vJcN2e5m2tlIhUDnVNVtFQAXef6wl1aI2TzFMZIloUzNQTATWMPqQIcqcJwYQWN0 CrIpWi2lGL3O2rBgg+5bKAb2p+jeI9t0BAifp2Y2ZbFmBE9KtRsiCNS1ODXhAzxB D0lBPMDP//CuzyS+uPFCnoNOkQNOHxXhD8MZ26RvvuIhz8WgD1mMK+/IZI4/obHf EpRIilbJYeEZoWK4t+ZzNqhaFDDRxpsk1FVpadDqakOf77mXkQhHrQMHDQkVaoDa kS6NN1YRhdXxRM4lYjy8FGaApyr4tXGQx2GHBPCJiHjtSyZ+hIS15y0VY0Wzh7dq OT1DzFFGzWM4nmN+cZ/tHtq4iTuVtiSP/dnJJa4SaKwzbBIfDcaglJ4ijij+4EXa 4qSABf02+Uf6YT4f9qhHn70jW0Ey7n5CvtidXSNK8Wpk5MwWNWJgWgNz+Dp2sYEw 2vgJwxv4C93A4dfpMZmPO1M26uqo1jgYghTl5ocCifQL1NLuv8cvp00Upc35IetL sruF1Df3RJFuSAmhPY6coQeOwinRhSA2L2CWFozd+dcH4VAWTKk= =nddK -----END PGP SIGNATURE-----