Home arrow Industry News arrow VoIP arrow Asterisk 1.0.12 released - Security Vulnerability Fix
Thursday, 20 November 2008
 
spacer.png, 0 kB
spacer.png, 0 kB
spacer.png, 0 kB
Asterisk 1.0.12 released - Security Vulnerability Fix
Thursday, 19 October 2006
The Asterisk Development team has released an update to Asterisk 1.0, Asterisk 1.0.12. This release contains a fix for a security vulnerability recently found in the chan_skinny channel driver (for Cisco SCCP phones). This vulnerability would enable an attacker to remotely execute code as the system user running Asterisk (frequently 'root'). The exploit does not require that the skinny.conf contain any valid phone entries, only that chan_skinny is loaded and operational. All Asterisk 1.0 users are urged to update to this release if they use the chan_skinny channel driver, or to stop loading it if it is not needed ('noload=>chan_skinny.so' in modules.conf will cause this behavior).
Read more...
 
spacer.png, 0 kB
     

© 2008 Intellect Information Technology Pty Ltd, Melbourne, Australia.

This page was loaded in 0.052 seconds.