Russell Bryant has posted details of a security issue in trunk:
A bug was fixed in IMAP_STORAGE in Asterisk trunk today in revision 71630. The problem was that the function, manager_list_voicemail_users() used the function count_messages() to determine the number of new messages waiting for a mailbox. However, this function was never defined for IMAP_STORAGE. Also, since we use lazy symbol resolution for our modules, the code could still actually build (with a warning, which is how I found it), and load happily into Asterisk. However, if you used this manager command, it will make Asterisk crash.
So, if your usage of Asterisk meets this criteria, you need to update:
1) You are using Asterisk trunk between revisions 66028 (about a month ago) and 71629
2) You are using IMAP_STORAGE for voicemail
3) You have the manager interface enabled
Also, I did not feel an official security advisory was justified for this since the problem never existed in a released version.
--
Russell Bryant
Software Engineer
Digium, Inc.
Current Rating: 0/10 (0 votes) Similar Articles (Based on Title)*-dev Developers meeting at von - September 10, 2006 Olle has posted details of the developers meeting at VON.
*-dev Open Source Pavilion at AstriCon: Your project wanted - July 31, 2009 John Todd has posted a note to let people know that Digium will give you a free booth and passes to Astricon for an Open Source project.
*-Dev: pseudo realtime and load issue - August 25, 2005 Steven Critchfield has posted details of a patch to reduce the risk of running Asterisk in pseudo realtime mode.
*-Announce: New issue tracker for handling licensing issues for Asterisk, Zaptel and related projects - February 7, 2006 The Asterisk Development Team have posted details of a new issue tracker for Asterisk and Zaptel etc.
Update on FBI Issue - Important - December 9, 2008 John Todd has sent a detailed note to the Asterisk developers list regarding the recent security release. Please post this wherever you can.
Workflow Guidelines for Asterisk Open Source Issue Tracker - September 25, 2009 The purpose of this document is to briefly describe the various statuses an issue can be placed in, and what that status means. In addition, the simple workflow and transition between statuses will be discussed.
Testers Needed Issue 16965 DBGet response does not end with a Complete event - March 19, 2010 Ryan Bullock is looking for people to test a patch he has written to fix the DBGet Action.
New IP phone snom 190 addresses security in VoIP - September 19, 2004 With the snom 190, the Berlin company addresses recent concerns about security of VoIP calls and adds productivity features for the business user.
New Security List - January 24, 2005 Steve Szmidt has posted details on the Asterisk-Security list.
VoIP-forum.com: NIST report urges caution with VoIP security - January 28, 2005 Olle's site has posted a link to an article on VoIP security.
Cisco tries to degrade the internet by attempting the patenting of security holes - July 9, 2005 There was a security hole discovered recently in the MTU Discovery process of ICMP packets.
Voip-News-Net: VoIP Security Roundup - January 27, 2006 There is an article on VoIP News Net discussing a few of the latest VoIP security threads.
*-Announce: Asterisk 1.2.9 and Asterisk 1.0.11 Released - Security Fix - June 6, 2006 The Asterisk Development Team today released Asterisk 1.2.9 and Asterisk 1.0.11 to address a security vulnerability in the IAX2 channel driver (chan_iax2).
Asterisk 1.2.9.1 and 1.0.11.1 Released -- Security Fix - June 7, 2006 The Asterisk release today has been rereleased.
Original Content (C) 2004-2010
Matt Riddell

Icons by: FastIcon.com
|
AstriDevCon: October 29th, Washington DC August 23, 2010 Average Vote: 10
John Todd has posted a note about the AstriDevCon conference which occurs within the Astricon conference.
Code Review: SRTP support for Asterisk March 12, 2009 Average Vote: 10
Terry Wilson has moved his SRTP branch onto the Digium review board.
The Everything Asterisk Video Collection August 5, 2010 Average Vote: 10
Steven Sokol has posted a blog entry on Asterisk Video Resources.
Voip-Forum: Lots of new articles March 12, 2005 Average Vote: 10
Oej's Voip-Forum.com site has posted lots of new news articles while I've been away. Hopefully you found them via the asterisk-docs site. If not I've bookmarked them for you.
Interview with Mark Spencer November 26, 2004 Average Vote: 9.9
We have managed to get an interview with Mark Spencer AKA Markster. Mark Spencer is the creator of Asterisk and by far the most active developer.
Asterisk and Kamailio realtime integration tutorial May 24, 2010 Average Vote: 9.9
Daniel-Constantin Mierla has posted a link to a tutorial on integrating Asterisk and Kamailio using realtime.
Asterisk and Kamailio (openser) realtime integration August 5, 2010 Average Vote: 9.8
Daniel-Constantin Mierla posted a writeup on combining Asterisk and Kamailio.
Asterisk IPv6 update February 1, 2010 Average Vote: 9.8
Olle has posted an update on IPV6 in Asterisk and a link to a blog post of his.
Proposal for T.38 transparent gateway design in Asterisk April 29, 2010 Average Vote: 9.8
Kevin Fleming has posted a proposed design for a transparent T.38 gateway for Asterisk:
Back to life July 21, 2010 Average Vote: 9.8
Hey all - I am back online after some pretty big projects which have taken all my time. Will be updating the Asterisk news over the next few days.
Announcing Adhearsion 0.8.5 August 25, 2010 Average Vote: 9.8
Ben Klang has posted a note about the latest release of Adhearsion - a framework for developing Asterisk based solutions using Ruby.
app_swift v2.0 released July 21, 2010 Average Vote: 9.8
Like a few of these news stories that I will be posting over the next couple of days this is a little old - hope it is not something you have already seen. This one is for a new version of the app_swift text-to-speech module for Asterisk 1.2, 1.4, and 1.6.
Monitoring Asterisk with Munin January 7, 2010 Average Vote: 9.7
I had a few requests for these munin plugins after some discussion on one of the Asterisk lists and thought people might like them.
GUI changes from Trixbox, FreePBX, 2600hz, BlueBox September 1, 2010 Average Vote: 9.7
Ok, bear with me on this one. If you understand all the ramifications, FreePBX has split to a new project called BlueBox contained within the 2600hz project. This obviously has implications for Trixbox that uses FreePBX to provide quite a bit of functionality.
Nerd Vittles: Finally... Installing Asterisk at Home on Your Windows PC February 9, 2006 Average Vote: 9.7
Ward Mundy has posted details of a how to for installing Asterisk at Home on a windows machine without removing windows.
libpri 1.4.11.4 Now Available September 3, 2010 The Asterisk Development Team has announced the release of libpri 1.4.11.4.
New CDR Stats Package September 1, 2010 This one has been a long time coming. A new CDR stats package from Star2Billing to replace the 7 year old stalwart for viewing Asterisk call detail records.
GUI changes from Trixbox, FreePBX, 2600hz, BlueBox September 1, 2010 Ok, bear with me on this one. If you understand all the ramifications, FreePBX has split to a new project called BlueBox contained within the 2600hz project. This obviously has implications for Trixbox that uses FreePBX to provide quite a bit of functionality.
RazorQuotePBP Asterisk Payment Module August 31, 2010 RazorQuote has sent us a press release about the launch of RazorQuotePBP, a native Asterisk module that allows any Asterisk connected device to accept credit card payments.
CloudVox: Install an open source Asterisk phone app and get 250 dollars August 30, 2010 CloudVox is running a competition for people to receive 250 dollars for writing up some documentation for Open Source applications on CloudVox - first in first served.
AstriCon approaches August 25, 2010 John Todd has posted a note about the upcoming AstriCon conference in Washington, DC, and the innovation awards.
Announcing Adhearsion 0.8.5 August 25, 2010 Ben Klang has posted a note about the latest release of Adhearsion - a framework for developing Asterisk based solutions using Ruby.
Asterisk 1.8.0-beta4 Now Available August 25, 2010 The Asterisk Development Team has announced the release of Asterisk 1.8.0-beta4.
AstriDevCon: October 29th, Washington DC August 23, 2010 John Todd has posted a note about the AstriDevCon conference which occurs within the Astricon conference.
The XV Commandments of IVR August 17, 2010 An update on the 15 tips for creating effective IVR systems by Allison Smith - the Voice of Asterisk.
|