Skip to content

Commit 165d805

Browse files
author
jnemeth
committed
Update to Asterisk 21.12.2:
Security update for PJSIP vulnerabilities. ## Change Log for Release asterisk-21.12.2 ### Links: - [Full ChangeLog](https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-21.12.2.html) - [GitHub Diff](asterisk/asterisk@21.12.1...21.12.2) ### Summary: - Commits: 1 - Commit Authors: 1 - Issues Resolved: 1 - Security Advisories Resolved: 0 ## Issue and Commit Detail: ### Closed Issues: - 1833: [bug]: Address security vulnerabilities in pjproject ### Commit List: - res_pjsip: Address pjproject security vulnerabilities ### Commit Details: #### res_pjsip: Address pjproject security vulnerabilities Author: Mike Bradeen Date: 2026-03-25 Address the following pjproject security vulnerabilities [GHSA-j29p-pvh2-pvqp - Buffer overflow in ICE with long username](GHSA-j29p-pvh2-pvqp) [GHSA-8fj4-fv9f-hjpc - Heap use-after-free in PJSIP presense subscription termination header](GHSA-8fj4-fv9f-hjpc) [GHSA-g88q-c2hm-q7p7 - ICE session use-after-free race conditions](GHSA-g88q-c2hm-q7p7) [GHSA-x5pq-qrp4-fmrj - Out-of-bounds read in SIP multipart parsing](GHSA-x5pq-qrp4-fmrj) Resolves: #1833
1 parent c31dd78 commit 165d805

3 files changed

Lines changed: 20 additions & 16 deletions

File tree

comms/asterisk21/Makefile

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# $NetBSD: Makefile,v 1.24 2026/02/16 02:49:34 jnemeth Exp $
1+
# $NetBSD: Makefile,v 1.25 2026/03/30 02:38:39 jnemeth Exp $
22
#
33
# NOTE: when updating this package, there are two places that sound
44
# tarballs need to be checked; look in ${WRKSRC}/sounds/Makefile
55
# to find out the current sound file versions
66
# Also look in ${WRKSRC}/third-party/versions.mak for pjproject
77

8-
DISTNAME= asterisk-21.12.1
8+
DISTNAME= asterisk-21.12.2
99
CATEGORIES= comms net audio
1010
MASTER_SITES= https://downloads.asterisk.org/pub/telephony/asterisk/
1111
MASTER_SITES+= https://downloads.asterisk.org/pub/telephony/asterisk/old-releases/
@@ -276,6 +276,7 @@ post-install:
276276
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.11.0.md ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
277277
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.12.0.md ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
278278
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.12.1.md ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
279+
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.12.2.md ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
279280
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.8.0.html ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
280281
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.9.0.html ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
281282
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.10.0.html ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
@@ -284,6 +285,7 @@ post-install:
284285
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.11.0.html ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
285286
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.12.0.html ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
286287
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.12.1.html ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
288+
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/ChangeLog-21.12.2.html ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
287289
${INSTALL_DATA} ${WRKSRC}/ChangeLogs/historical/CHANGES ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
288290
${INSTALL_DATA} ${WRKSRC}/LICENSE ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}
289291
${INSTALL_DATA} ${WRKSRC}/README-SERIOUSLY.bestpractices.md ${DESTDIR}${PREFIX}/share/doc/${PKGBASE}

comms/asterisk21/PLIST

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
@comment $NetBSD: PLIST,v 1.10 2026/02/16 02:49:34 jnemeth Exp $
1+
@comment $NetBSD: PLIST,v 1.11 2026/03/30 02:38:39 jnemeth Exp $
22
lib/asterisk/libasteriskpj.so
33
lib/asterisk/libasteriskpj.so.2
44
lib/asterisk/modules/app_adsiprog.so
@@ -2333,6 +2333,8 @@ share/doc/asterisk/ChangeLog-21.12.0.html
23332333
share/doc/asterisk/ChangeLog-21.12.0.md
23342334
share/doc/asterisk/ChangeLog-21.12.1.html
23352335
share/doc/asterisk/ChangeLog-21.12.1.md
2336+
share/doc/asterisk/ChangeLog-21.12.2.html
2337+
share/doc/asterisk/ChangeLog-21.12.2.md
23362338
share/doc/asterisk/ChangeLog-21.2.0.md
23372339
share/doc/asterisk/ChangeLog-21.3.0.md
23382340
share/doc/asterisk/ChangeLog-21.3.1.md

comms/asterisk21/distinfo

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,17 @@
1-
$NetBSD: distinfo,v 1.11 2026/02/16 02:49:34 jnemeth Exp $
1+
$NetBSD: distinfo,v 1.12 2026/03/30 02:38:39 jnemeth Exp $
22

3-
BLAKE2s (asterisk-21.12.1/asterisk-21.12.1.tar.gz) = 9dfc85c6f103e8dc7ce4ab535d35cc1bb1707f922393fadec110fd8d3c86285e
4-
SHA512 (asterisk-21.12.1/asterisk-21.12.1.tar.gz) = aad2072aa3ea0a1cc31f74204bf2f9a907c2c103b328cba5fb69311f213ca3ddb0862398c8a970a8702a0075b3be38c587e4f944c56aa385eb38397d57b991af
5-
Size (asterisk-21.12.1/asterisk-21.12.1.tar.gz) = 26606158 bytes
6-
BLAKE2s (asterisk-21.12.1/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 3f7e5fe212d7e7cdca14c52527a2552311ab7762c3f1464b09ddedc7c66aebde
7-
SHA512 (asterisk-21.12.1/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 3f2f7bf3d5bce3544bc013f913c352f0204a3ce96239987403eb9dce8bc87e64a61d437762323a422a87b2fad1f3bf3e7a5f3d0d340f912a1b1dbfea9479d41d
8-
Size (asterisk-21.12.1/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 4253587 bytes
9-
BLAKE2s (asterisk-21.12.1/pjproject-2.15.1.md5) = 1bdb00828816aff69f43eaacd084bd7d0a48670af33110bd0cd6325ead45aa48
10-
SHA512 (asterisk-21.12.1/pjproject-2.15.1.md5) = 75963b64e702a5810fd5b8b574a07396cab1a87543d806135e7a9b9762d35129354f99283252f40ad75a6a94cd1921f164ed8e63174de0c5430e5c6913d21744
11-
Size (asterisk-21.12.1/pjproject-2.15.1.md5) = 172 bytes
12-
BLAKE2s (asterisk-21.12.1/pjproject-2.15.1.tar.bz2) = 2bcb38884531f0be966c78b6bac45ac63d8c612c060da91c584d192fe0fdf9cd
13-
SHA512 (asterisk-21.12.1/pjproject-2.15.1.tar.bz2) = c080eb44b49fccadb1c76ff2b3221935b0d531a1e2087b47c21b4ec2cdd8ee0e62b13c334495c9c759b348a0792204611987089a6aa6264999f0116aec8dbdfd
14-
Size (asterisk-21.12.1/pjproject-2.15.1.tar.bz2) = 8492214 bytes
3+
BLAKE2s (asterisk-21.12.2/asterisk-21.12.2.tar.gz) = ee55a88bf1c85c068dbfc4346ef2cda11cb6ecf61916e046a78cee411f4fe90f
4+
SHA512 (asterisk-21.12.2/asterisk-21.12.2.tar.gz) = 821a78ea484fc43d2745a4e261663fcfd776d699df99bc5c995507aacab8c0f852952b217b877d9897f4308e9528d08a4009acb9717eec538ee693e9e9d8eac4
5+
Size (asterisk-21.12.2/asterisk-21.12.2.tar.gz) = 26608590 bytes
6+
BLAKE2s (asterisk-21.12.2/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 3f7e5fe212d7e7cdca14c52527a2552311ab7762c3f1464b09ddedc7c66aebde
7+
SHA512 (asterisk-21.12.2/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 3f2f7bf3d5bce3544bc013f913c352f0204a3ce96239987403eb9dce8bc87e64a61d437762323a422a87b2fad1f3bf3e7a5f3d0d340f912a1b1dbfea9479d41d
8+
Size (asterisk-21.12.2/asterisk-extra-sounds-en-gsm-1.5.2.tar.gz) = 4253587 bytes
9+
BLAKE2s (asterisk-21.12.2/pjproject-2.15.1.md5) = 1bdb00828816aff69f43eaacd084bd7d0a48670af33110bd0cd6325ead45aa48
10+
SHA512 (asterisk-21.12.2/pjproject-2.15.1.md5) = 75963b64e702a5810fd5b8b574a07396cab1a87543d806135e7a9b9762d35129354f99283252f40ad75a6a94cd1921f164ed8e63174de0c5430e5c6913d21744
11+
Size (asterisk-21.12.2/pjproject-2.15.1.md5) = 172 bytes
12+
BLAKE2s (asterisk-21.12.2/pjproject-2.15.1.tar.bz2) = 2bcb38884531f0be966c78b6bac45ac63d8c612c060da91c584d192fe0fdf9cd
13+
SHA512 (asterisk-21.12.2/pjproject-2.15.1.tar.bz2) = c080eb44b49fccadb1c76ff2b3221935b0d531a1e2087b47c21b4ec2cdd8ee0e62b13c334495c9c759b348a0792204611987089a6aa6264999f0116aec8dbdfd
14+
Size (asterisk-21.12.2/pjproject-2.15.1.tar.bz2) = 8492214 bytes
1515
SHA1 (patch-Makefile) = 5cf3b6937ec23a82e4d056b91e493a36bc1089b9
1616
SHA1 (patch-addons_chan__ooh323.c) = 1775da7ca2129a962ed460bd1e78ba3ce6afa62c
1717
SHA1 (patch-apps_app__adsiprog.c) = 031139e5cd1ef6bb2afb0a74fee3d752eded0a2c

0 commit comments

Comments
 (0)