<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><br><div>Begin forwarded message:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>From: </b></span><span style="font-family:'Helvetica'; font-size:medium;">Asterisk Development Team <<a href="mailto:asteriskteam@digium.com">asteriskteam@digium.com</a>><br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>Date: </b></span><span style="font-family:'Helvetica'; font-size:medium;">28 de junho de 2011 17:54:57 BRT<br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>To: </b></span><span style="font-family:'Helvetica'; font-size:medium;"><a href="mailto:asteriskteam@digium.com">asteriskteam@digium.com</a><br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>Subject: </b></span><span style="font-family:'Helvetica'; font-size:medium;"><b>[asterisk-dev] Asterisk 1.4.41.2, 1.6.2.18.2, and 1.8.4.4 Now Available (Security Releases)</b><br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>Reply-To: </b></span><span style="font-family:'Helvetica'; font-size:medium;">Asterisk Developers Mailing List <<a href="mailto:asterisk-dev@lists.digium.com">asterisk-dev@lists.digium.com</a>><br></span></div><br><div>The Asterisk Development Team has announced the release of Asterisk versions<br>1.4.41.2, 1.6.2.18.2, and 1.8.4.4, which are security releases.<br><br>These releases are available for immediate download at<br><a href="http://downloads.asterisk.org/pub/telephony/asterisk/releases">http://downloads.asterisk.org/pub/telephony/asterisk/releases</a><br><br>The release of Asterisk 1.4.41.2, 1.6.2.18.2, and 1.8.4.4 resolves the<br>following issue:<br><br>AST-2011-011: Asterisk may respond differently to SIP requests from an<br>invalid SIP user than it does to a user configured on the system, even when the<br>alwaysauthreject option is set in the configuration. This can leak information<br>about what SIP users are valid on the Asterisk system.<br><br>For more information about the details of this vulnerability, please read<br>the security advisory AST-2011-011, which was released at the same time as this<br>announcement.<br><br>For a full list of changes in the current releases, please see the ChangeLog:<br><br>http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.4.41.2<br>http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.6.2.18.2<br>http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.4.4<br><br>Security advisory AST-2011-011 is available at:<br><br>http://downloads.asterisk.org/pub/security/AST-2011-011.pdf<br><br>Thank you for your continued support of Asterisk!<br><br>--<br>_____________________________________________________________________<br>-- Bandwidth and Colocation Provided by http://www.api-digital.com --<br><br>asterisk-dev mailing list<br>To UNSUBSCRIBE or update options visit:<br> http://lists.digium.com/mailman/listinfo/asterisk-dev<br></div></blockquote></div><br></body></html>