-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 02 Feb 2025 19:28:42 +0100 Source: asterisk Architecture: source Version: 1:16.28.0~dfsg-0+deb11u6 Distribution: bullseye-security Urgency: medium Maintainer: Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org> Changed-By: Daniel Leidert <dleidert@debian.org> Changes: asterisk (1:16.28.0~dfsg-0+deb11u6) bullseye-security; urgency=medium . * Non-maintainer upload by the Debian LTS Team. * d/patches/CVE-2024-53566.patch: Add patch to fix CVE-2024-53566.patch. - It is possible to access files outside the configuration directory via AMI and path traversal even when live_dangerously is not enabled. * d/tests/control: Allow output on STDERR. Checksums-Sha1: b3bcf59a268fa209d2fc806a1caa423473ea4b01 4208 asterisk_16.28.0~dfsg-0+deb11u6.dsc 49670212bc11af42239eff3b2e6fa705bf6d603a 6873592 asterisk_16.28.0~dfsg-0+deb11u6.debian.tar.xz 9ae495a963637753fdb2a45480719fa35ba2748e 29242 asterisk_16.28.0~dfsg-0+deb11u6_amd64.buildinfo Checksums-Sha256: c3303b7e521ecad9779b604a8be6f99a22b2139a9142e66490bda7a5607d82f5 4208 asterisk_16.28.0~dfsg-0+deb11u6.dsc 1dee86d352f1fc8ed07c1c5e51fe8220a433e486d44cd3e53f8ced4d444bbd5d 6873592 asterisk_16.28.0~dfsg-0+deb11u6.debian.tar.xz a9524a2d98bc53be938dee31b9cb1736bce2302b05d2aed3041f0f67f8926a50 29242 asterisk_16.28.0~dfsg-0+deb11u6_amd64.buildinfo Files: 4a203af00bd86b817bc5d4527f840020 4208 comm optional asterisk_16.28.0~dfsg-0+deb11u6.dsc efcaacc3fd7760b15d36a59c9c7035ca 6873592 comm optional asterisk_16.28.0~dfsg-0+deb11u6.debian.tar.xz c7c9b0d4925d238681bb986197aa4d2e 29242 comm optional asterisk_16.28.0~dfsg-0+deb11u6_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmej7bIACgkQS80FZ8KW 0F2Ctg/+J1zTFgwkDhQHooJb4RfkawpR6dKaymggeXc/BONyGQStvGilTtX+jNGT 5O6ue5tYDmHkyaO+JWJDI5VNrzH3wJMTPtAcs2p799K/SOGSqRP1QaRs3Hc9djLq feFE0JHmfPaSOfk+Y4qqChEiC2TnZYhdVDCQozMIzWWZ86ehSYaRl9f59lIYiITt ncT+pNgWC0Ug1fY/0goAjXYKIlsoe5zc5xGSithh82RZUl+Gt0H828l3h6vS44qQ bwMzmxtUiABMGN2EuTZOE0pkar0ImAgML9PNXn0QWppR2LelKByAgkSC1eUrU3Om TfcFPODj8Sx/E3y4ZcbeFTxEEa4NzrfDablvw0YpXYrsNZiR0oZjUp3gLResUiiq nz3MP6cL5dCxPj1EJgykAAmhiyxYmsxYuvcIt0IwmkKXC/MKj2jz00FzE5hRFTf1 ZWI4ydaqJ6NfySDVHbZNrfcWmgfUhu9YP44RQUhHe2MX0E134K2cyGRvHhwE9TwY DAXwd/OOj7ClnD08Q/uOv+uxpxvXHYEwXoBFDA4MxpqujmsbN1R28Dsj0bNMmwuW Z7YI7y2Zh2a18ckpruC8lW4/CA9rejmCsRG8Q9hqLQvfcIP5I/vXwdH3srmB14v8 67IvF1zXTUxLShz9yamNAWaSCalpJRSUXoQvPrgWiXj9MzezZxs= =WoPK -----END PGP SIGNATURE-----