Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Asterisk IAX2 VoIP PBX and multiple IAX clients DoS

  [Full-disclosure] [ GLSA 200606-30 ] Kiax: Arbitrary code execution

  CORE-2006-0327: IAXclient truncated frames vulnerabilities

  CORE-2006-0330: Asterisk PBX truncated video frame vulnerability

From:Matt Riddell (IT) <matt.riddell_(at)_sineapps.com>
Date:07.06.2006
Subject:Asterisk 1.2.9 and Asterisk 1.0.11 Released - Security Fix

The Asterisk Development Team today released Asterisk 1.2.9 and Asterisk
1.0.11 to address a security vulnerability in the IAX2 channel driver
(chan_iax2). The vulnerability affects all users with IAX2 clients that
might be compromised or used by a malicious user, and can lead to denial
of service attacks and random Asterisk server crashes via a relatively
trivial exploit.

All users are urged to upgrade as soon as they can practically do so, or
ensure that they don't expose IAX2 services to the public if it is not
necessary.

The release files are available in the usual place (ftp.digium.com), as
both tarballs and patch files relative to the last release. In addition,
both the tarballs and the patch files have been signed using GPG keys of
the release maintainers, so that you can ensure their authenticity.

Thank you for your support of Asterisk!

--
Cheers,

Matt Riddell
_______________________________________________

http://www.sineapps.com/news.php (Daily Asterisk News - html)
http://freevoip.gedameurope.com (Free Asterisk Voip Community)
http://www.sineapps.com/rssfeed.php (Daily Asterisk News - rss)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru