Asterisk Security Team
2007-Nov-29 22:10 UTC
[asterisk-users] Asterisk 1.4.15 and 1.2.25 Released
The Asterisk.org development team has released Asterisk versions 1.4.15 and 1.2.25. These releases contain two fixes for security issues. http://downloads.digium.com/pub/asa/AST-2007-025.pdf * This is a SQL injection vulnerability in the res_config_pgsql module. Default installations of Asterisk are not affected. However, any system using the Postgres Realtime Engine may be remotely exploitable. This issue only affects Asterisk 1.4, as this module was not in Asterisk 1.2. http://downloads.digium.com/pub/asa/AST-2007-026.pdf * This is another SQL injection vulnerability. The input for the ANI and DNIS fields were not properly escaped. Default installations of Asterisk are not vulnerable. However, systems that use the Postgres CDR logging module may be remotely exploitable. This issue affects both Asterisk 1.2 and 1.4. Both releases are available on http://downloads.digium.com. Thank you very much for your support!