libosip2 (4.1.0-2.1) unstable; urgency=medium * Non-maintainer upload to fix security issues (Closes: #860287) * CVE-2016-10324: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c. * CVE-2016-10325: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS. * CVE-2016-10326: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS. * CVE-2017-7853: In libosip2 in GNU oSIP 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS. -- Antoine Beaupré Fri, 14 Apr 2017 16:21:21 -0400 libosip2 (4.1.0-2) unstable; urgency=low * Upload to unstable - coordinated through debian-release -- Mark Purcell Wed, 25 Jun 2014 21:54:30 +1000 libosip2 (4.1.0-1) experimental; urgency=low * New upstream release * NEW package libosip2-11 - match soname * Fix "use dh-autoreconf instead of autotools-dev to fix FTBFS on ppc64el" patch from ~logan (Closes: #735640) * Drop all debian/patches - included upstream -- Mark Purcell Mon, 20 Jan 2014 20:24:38 +1100 libosip2 (4.0.0-3) unstable; urgency=low * Fix "FTBFS on hurd-i386" patch supplied by Pino (Closes: #715196) -- Mark Purcell Sun, 04 Aug 2013 10:25:43 +1000 libosip2 (4.0.0-2) unstable; urgency=low * Upload to unstable * Update debian/control - fix Vcs & Standards-Version: -- Mark Purcell Sun, 12 May 2013 18:41:44 +1000 libosip2 (4.0.0-1) experimental; urgency=low * New upstream release * NEW package libosip2-10 - match soname * Drop obsolete spelling-error-in-manpage.diff * Refresh manpage-section-mismatch.patch -- Mark Purcell Sun, 23 Dec 2012 13:45:52 +1100 libosip2 (3.6.0-4) unstable; urgency=low * weezey polish * Update Standards-Version: 3.9.3 * Refresh manpage-section-mismatch.patch * debian/compat -> 9 - hardening & multiarch -- Mark Purcell Sun, 24 Jun 2012 20:57:55 +1000 libosip2 (3.6.0-3) unstable; urgency=low * Upload to unstable - debian-release endorsed * Fix minor spelling-error.diff -- Mark Purcell Sun, 26 Feb 2012 07:52:37 +1100 libosip2 (3.6.0-2) experimental; urgency=low * Fix "Resolve unresolved symbols in shared libraries" debian/rules: export EXTRA_LIB=-lpthread (Closes: #558915) -- Mark Purcell Sat, 08 Oct 2011 14:06:34 +1100 libosip2 (3.6.0-1) experimental; urgency=low * New upstream release - NEW package libosip2-7 - soname bump * docs: drop duplicate-changelog-files ChangeLog * Drop content of dependancy_libs (sed -i) - Fixes "Emptying dependency_libs in .la files" (Closes: #633334) * Switch to dh 7 * Switch to dpkg-source 3.0 (quilt) format * Upgrade to Standards Version 3.9.2 * Upgrade debian/watch to v3 * copyright-refers-to-symlink-license - Updated debian/copyright -> LGPL-2.1 * Add osip.1 to libosip2-dev -- Mark Purcell Sat, 08 Oct 2011 13:54:35 +1100 libosip2 (3.5.0-1) experimental; urgency=low * New upstream release * NEW package libosip2-6 - soname bump * debian/compat -> 7 -- Mark Purcell Sat, 29 Jan 2011 15:08:04 +1000 libosip2 (3.3.0-1) unstable; urgency=low * New upstream release - libosip2 transition * Cleanup Uploaders: (Closes: #508850) * Upstream includes ignore-debian-Makefile.in.patch -- Mark Purcell Sun, 08 Mar 2009 15:36:40 +1100 libosip2 (3.2.0-1) experimental; urgency=low * New upstream release [ Patrick Matthäi ] * Bumped to Standards-Version 3.8.0. * Removed some more useless whitespaces at EOL in debian/control. [ Mark Purcell ] * NEW package libosip2-4 to match upstream soname * Add uclean(1) call to get-orig-source target * Add manpage-section-mismatch.patch -- Mark Purcell Sat, 15 Nov 2008 22:11:57 +1100 libosip2 (3.1.0-1) unstable; urgency=low * New upstream release [ Kilian Krause ] * Update Maintainer to Debian VoIP Team. [ Mark Purcell ] * Cleanup get-orig-source VARS * Ran uclean(1) over .orig.tar.gz * Ignore upstream debian/Makefile.in - ignore-debian-Makefile.in.patch * Bump packagename to libosip2-3deb (libosip2-3 is used in etch) - package-name-doesnt-match-sonames libosip2-3 - Conflicts: Replaces: etch libosip3 (<< 3.0) same soname * Remove debian/dirs - lintian: package-contains-empty-directory -- Mark Purcell Fri, 18 Apr 2008 16:04:23 +1000 libosip2 (3.0.3-2-1) unstable; urgency=low * New Upstream Release [ Mikael Magnusson ] * Fix debian/rules print-version and get-orig-source [ Mark Purcell ] * Bump soname (backwards libosip2-2) - linphone-nox: nox client fails to start (Closes: #439196) - libosip2-3: package-name-doesnt-match-sonames libosip2-2 (Closes: #439600) * linda: debhelper.mk needs Build-Depends: (>= 4.1.0) * Dump Provides:/ Conflicts: libosip2feature209 not used in Debian * Add Conflicts: libosip2-3 (>> 3.0) for missed soname bump -- Mark Purcell Fri, 31 Aug 2007 22:02:47 +0100 libosip2 (3.0.3-2) unstable; urgency=low * Build-Depends: cdbs -- Mark Purcell Sun, 19 Aug 2007 12:27:34 +0100 libosip2 (3.0.3-1) unstable; urgency=low * New upstream release (Closes: #421509) [ Kilian Krause ] * debian/control: - Import into pkg-voip. - Use binary:Version stanza to allow clean binNMUs. Bump to dpkg-dev (>= 1.13.19) * debian/watch: Update. [ Mark Purcell ] * libosip2-dev Recommends: pkg-config * Switch to cdbs * Ack NMU - libosip2-dev: libosip2.pc is missing (Closes: #328825) - libosip2-3: please provide osip.1 upstream man page (Closes: #366037) - Link in description doesn't exist (Closes: #352251) * Add Build-Depends: docbook-to-man to generate osip(1) * Add Build-Depends: autotools-dev * move osip.1 to -dev package, allows future upgrades of libs -- Mark Purcell Sun, 19 Aug 2007 11:43:12 +0100 libosip2 (2.2.2-3.1) unstable; urgency=low * Non-maintainer upload. * BTS old bugs: + Include libosip2.pc in -dev package (Closes: #328825) + Link libosip2.so.3.0.0 against libpthread.so (Closes: #356330) + Fix Links in debian/control: fsf.org => gnu.org (Closes: #352251) * Remove debian/*.ex files (Closes: #366036). * Remove debian/libosip2.* files. * switch to dh_install in debian/rules: + enable --list-missing to catch non installed files (like osip.1). + .files/.install were not in sync. * Also bump Standards-Version to 3.6.2. * Install upstream man page osip.1 (Closes: #366037). * Fix FSF address in debian/copyright. * Make debian/copyright complete (missing copyright statement for osip_md5.{h,c}) (Closes: #366034). -- Pierre Habouzit Wed, 24 May 2006 22:04:05 +0200 libosip2 (2.2.2-3) unstable; urgency=medium * Revert NMU -- Anand Kumria Tue, 18 Apr 2006 13:44:28 +1000 libosip2 (2.2.2-2) unstable; urgency=low * Change Build-Dep to automake1.8 (Closes: #335134) -- Anand Kumria Sat, 31 Dec 2005 13:07:36 +1100 libosip2 (2.2.2-1) unstable; urgency=low [ Aymeric MOIZARD ] * parser speed improvements * replace mutex with critical section on windows for performance. * fix a bug in the parser for empty header (also store empty Accept header) * improve mime support. * improve sipfrag support. * add NULL checks (uris...). * patch for PSOS support. [ ARAKI Yasuhiro ] * new upstream release. -- ARAKI Yasuhiro Wed, 21 Dec 2005 18:36:25 +0900 libosip2 (2.2.1-1) unstable; urgency=low * fix a potential mem leak content_type and osip_message_parse. * fix osip_body_clone method (add terminating NULL) * fix for binary support when multipart is used. * automatic check for reliable protocol SCTP and TLS. * avoid inclusion so user can (and must) now include either or before including -- Aymeric MOIZARD Tue, 12 Jul 2005 13:04:32 +0100 libosip2 (2.2.0+2.2.1pre4-2) unstable; urgency=low * Maintainer change: Anand Kumria to ARAKI Yasuhiro . -- ARAKI Yasuhiro Mon, 25 Apr 2005 14:11:33 +0900 libosip2 (2.2.0+2.2.1pre4-1) unstable; urgency=low * New upstream release * fix osip_body_clone doesn't NULL terminate the copied body. Reported by Mikael Magnusson. (Close: #305729) * Maintainer change: Anand Kumria to ARAKI Yasuhiro . -- ARAKI Yasuhiro Fri, 22 Apr 2005 15:33:12 +0900 libosip2 (2.2.0-1) unstable; urgency=low * remove #ifdef OSIP_RETRANSMIT_2XX to always compile it. * initialize remote_contact_uri when dialog is built with notify. * allow very short attachements. * new macros allocators. * remove use of alloca in the parser. * fix memory bug when realloc is needed on large message. * remove useless prototypes. * fix memory access in parser. * API slightly broken to enable support for binary data. * improvements of the sip message test suite. * ABI change to 3 -- ARAKI Yasuhiro Fri, 4 Feb 2005 14:46:08 +0900 libosip2 (2.0.9-2) unstable; urgency=low * fix for ABI change (close: #285079) -- ARAKI Yasuhiro Sat, 11 Dec 2004 15:20:14 +0900 libosip2 (2.0.9-1) unstable; urgency=low * New upstream release -- ARAKI Yasuhiro Thu, 9 Dec 2004 18:09:09 +0900 libosip2 (2.0.6-2) unstable; urgency=low * fix: lack "libosip2.so" install for libosip2-dev. -- ARAKI Yasuhiro Tue, 23 Mar 2004 15:29:12 +0900 libosip2 (2.0.6-1) unstable; urgency=low * New upstream release (close: #238263) * Co-maintainer add: ARAKI Yasuhiro -- ARAKI Yasuhiro Thu, 18 Mar 2004 11:56:11 +0900 libosip2 (2.0.5-2) unstable; urgency=low * Build depend on automake1.6 too -- Anand Kumria Sun, 28 Dec 2003 13:17:07 +1100 libosip2 (2.0.5-1) unstable; urgency=low * New upstream release (and change of source name) * For the life of me I couldn't see what the patch was but I believe this will fix the problem (closes: #215606, 219421) -- Anand Kumria Sat, 27 Dec 2003 11:07:33 +1100 osip (2.0.4-1) unstable; urgency=low * New upstream release -- Anand Kumria Sun, 11 Oct 2003 05:17:51 +1000 osip (2.0.1.2-1) unstable; urgency=low * Initial Release. -- Anand Kumria Tue, 30 Sep 2003 16:09:51 +1000