Bug#847635: AST-2016-009: SIP header whitespace with proxy

2016-12-11 Thread Dara Adib
Bernhard Schmidt wrote: > The Debian Security team thinks that this bug does not warrant an > immediate security update. I tend to agree, since the circumstances of > this to be exploitable are very special. > > Do you agree? We will likely still fix it in Jessie in a point release, > and we will

Bug#847635: AST-2016-009: SIP header whitespace with proxy

2016-12-10 Thread Bernhard Schmidt
Control: forcemerge 847668 -1 On Fri, Dec 09, 2016 at 11:30:27PM -0500, Dara Adib wrote: Hello Dara, > Package: asterisk > Version: 1:11.13.1~dfsg-2+deb8u1 > Severity: important > Tags: security patch > > https://security-tracker.debian.org/tracker/TEMP-000-5567B0 >

Bug#847635: AST-2016-009: SIP header whitespace with proxy

2016-12-09 Thread Dara Adib
Package: asterisk Version: 1:11.13.1~dfsg-2+deb8u1 Severity: important Tags: security patch https://security-tracker.debian.org/tracker/TEMP-000-5567B0 http://downloads.asterisk.org/pub/security/AST-2016-009.html I believe this is the patch: https://gerrit.asterisk.org/4587 Thanks!