• News
  • Idefisk
  • Tools
  • Tutorials
  • Forum
  • Reviews
  • VoIP Providers
  • Archives
  • Gallery
ZOIPER SIP softphone

 
Home Post
  • All News
  • Voip hardware
  • Voip software
  • Business
  • Technology
  • Voip regulatory
  • Asterisk
  • Asterisk third party
  • Miscellaneous
news.asteriskguru.com
(Critical Updates) Asterisk 1.2.27, 1.4.18.1, 1.4.19-rc3, 1.6.0-beta6 Released
19/Mar/2008 11:52 / news.asteriskguru.com
section: Asterisk

The Asterisk.org development team has released four new versions of Asterisk to address critical security vulnerabilities.

AST-2008-002 details two buffer overflows that were discovered in RTP codec payload type handling.

* http://downloads.digium.com/pub/security/AST-2008-002.pdf
* All users of SIP in Asterisk 1.4 and 1.6 are affected.

AST-2008-003 details a vulnerability which allows an attacker to bypass SIP authentication and to make a call into the context specified in the general section of sip.conf.

* http://downloads.digium.com/pub/security/AST-2008-003.pdf
* All users of SIP in Asterisk 1.0, 1.2, 1.4, or 1.6 are affected.

AST-2008-004 details some format string vulnerabilities that were found in the code handling the Asterisk logger and the Asterisk manager interface.

* http://downloads.digium.com/pub/security/AST-2008-004.pdf
* All users of Asterisk 1.6 are affected.

Asterisk 1.2.27 and 1.4.18.1 are releases that only contain changes to fix these security vulnerabilities.

In addition to fixes for these security issues, 1.4.19-rc3 and 1.6.0-beta6 contain a number of other bug fixes over the previous release candidates and beta releases for the upcoming 1.4.19 and 1.6.0 releases.

We encourage all affected users of these security vulnerabilities to upgrade their installations as time permits.

Thank you for your continued support of Asterisk!

Source: Read original source

 
News Comments
 
Add Comment
Name:
Email:
Comment:
In order to prevent automatic posting on our website, we kindly request you to type in the number you see in the picture below.
Image Verification:
 

More Asterisk Headlines:

  • Asterisk 1.2.28, 1.4.19.1, and 1.6.0-beta8 Released
    section: Asterisk
  • Zaptel 1.2.25 and 1.4.10 released
    section: Asterisk
  • Asterisk 1.4.19 and Asterisk-addons 1.6.0-beta3 Released
    section: Asterisk
  • Asterisk 1.4.19-rc4 and 1.6.0-beta7 Now Available
    section: Asterisk
  • AsteriskNOW 1.0.2 Available!!
    section: Asterisk
  • News Archives (older news)

Latest Tutorials:

  • VMAuthenticate (dialplan application)
    added 01/Mar/2008 15:57
  • Siptronic ST-530
    added 06/Nov/2007 17:57
  • Siemens C455 IP hardphone
    added 05/Nov/2007 10:24
  • Zoiper
    added 22/Oct/2007 17:53
  • Grandstream GXP-2020
    added 15/Oct/2007 18:17

Latest Comments:

  • I think, that it is really a bad thing t...
    tutorial: Softphones
  • where can i find the asterisk admin manu...
    section: Asterisk third party
  • Voice mail prompts callers to hang up or...
    tutorial: Asterisk Voicemail
  • Hi i tray to use the script, but rearly...
    tutorial: Automatically call all phones to check if they work
  • Nothing for now...
    tutorial: MediaX IAX2 softphone

RSS/Atom - Asterisk

Filter Filter Filter Filter
 
contact us at: support@asteriskguru.com - asterisKGuru.com © all rights reserved   |   *asterisk is registered trademark of © Digium™