[AsteriskBrasil] Fwd: [asterisk-dev] Asterisk 1.4.17 Released
Denis Galvão
denisgalvao em gmail.com
Sexta Janeiro 4 12:26:03 BRST 2008
Para conhecimento.
--
Denis Galvão
AsteriskBrasil.org
Ajude a comunidade AsteriskBrasil.org, compre uma camiseta!
http://www.voipmania.com.br
Begin forwarded message:
> From: The Asterisk Development Team <asteriskteam em digium.com>
> Date: 02 de janeiro de 2008 19h39min4s GMT-02:00
> To: undisclosed-recipients:;
> Subject: [asterisk-dev] Asterisk 1.4.17 Released
> Reply-To: Asterisk Developers Mailing List <asterisk-
> dev em lists.digium.com>
>
> The Asterisk.org development team has released Asterisk version
> 1.4.17. This
> release contains a fix for a SIP security issue, as well as a
> number of other
> bug fixes.
>
> The security issue is documented in the published security advisory,
> AST-2008-001. The vulnerability allows an attacker to cause a
> crash in the SIP
> channel driver with a properly crafted transfer. This issue
> requires an
> authenticated session that allows transfers to be exploited. If
> unauthenticated
> calls with transfer capability are allowed, then this issue could
> be exploited
> with an unauthenticated session. Also, this issue only affects
> Asterisk 1.4.
> Asterisk 1.2 is not affected. Systems that do not use chan_sip are
> also not
> affected.
>
> The security advisory is available at
> http://downloads.digium.com/pub/security/AST-2008-001.pdf.
>
> The release is available for immediate download from
> http://downloads.digium.com/pub/telephony/asterisk/.
>
> Thank you for your support!
>
> _______________________________________________
> --Bandwidth and Colocation Provided by http://www.api-digital.com--
>
> asterisk-dev mailing list
> To UNSUBSCRIBE or update options visit:
> http://lists.digium.com/mailman/listinfo/asterisk-dev
More information about the AsteriskBrasil
mailing list