[AsteriskBrasil] Fwd: [asterisk-dev] Asterisk 1.4.17 Released

Denis Galvão denisgalvao em gmail.com
Sexta Janeiro 4 12:26:03 BRST 2008


Para conhecimento.
--
Denis Galvão
AsteriskBrasil.org

Ajude a comunidade AsteriskBrasil.org, compre uma camiseta!
http://www.voipmania.com.br


Begin forwarded message:

> From: The Asterisk Development Team <asteriskteam em digium.com>
> Date: 02 de janeiro de 2008 19h39min4s GMT-02:00
> To: undisclosed-recipients:;
> Subject: [asterisk-dev] Asterisk 1.4.17 Released
> Reply-To: Asterisk Developers Mailing List <asterisk- 
> dev em lists.digium.com>
>
> The Asterisk.org development team has released Asterisk version  
> 1.4.17.  This
> release contains a fix for a SIP security issue, as well as a  
> number of other
> bug fixes.
>
> The security issue is documented in the published security advisory,
> AST-2008-001.  The vulnerability allows an attacker to cause a  
> crash in the SIP
> channel driver with a properly crafted transfer.  This issue  
> requires an
> authenticated session that allows transfers to be exploited.  If  
> unauthenticated
> calls with transfer capability are allowed, then this issue could  
> be exploited
> with an unauthenticated session.  Also, this issue only affects  
> Asterisk 1.4.
> Asterisk 1.2 is not affected.  Systems that do not use chan_sip are  
> also not
> affected.
>
> The security advisory is available at
> http://downloads.digium.com/pub/security/AST-2008-001.pdf.
>
> The release is available for immediate download from
> http://downloads.digium.com/pub/telephony/asterisk/.
>
> Thank you for your support!
>
> _______________________________________________
> --Bandwidth and Colocation Provided by http://www.api-digital.com--
>
> asterisk-dev mailing list
> To UNSUBSCRIBE or update options visit:
>    http://lists.digium.com/mailman/listinfo/asterisk-dev



More information about the AsteriskBrasil mailing list