Huge thanks to Joshua Colp for mirroring services

Security Issue in Asterisk trunk IMAP_STORAGE

Share on Twitter Digg this story Click to view a printable version Mon, 25 Jun 2007 20:06:24 -0300

Russell Bryant has posted details of a security issue in trunk:

A bug was fixed in IMAP_STORAGE in Asterisk trunk today in revision 71630. The problem was that the function, manager_list_voicemail_users() used the function count_messages() to determine the number of new messages waiting for a mailbox. However, this function was never defined for IMAP_STORAGE. Also, since we use lazy symbol resolution for our modules, the code could still actually build (with a warning, which is how I found it), and load happily into Asterisk. However, if you used this manager command, it will make Asterisk crash.

So, if your usage of Asterisk meets this criteria, you need to update:

1) You are using Asterisk trunk between revisions 66028 (about a month ago) and 71629

2) You are using IMAP_STORAGE for voicemail

3) You have the manager interface enabled

Also, I did not feel an official security advisory was justified for this since the problem never existed in a released version.

--
Russell Bryant
Software Engineer
Digium, Inc.


You haven't voted yet! Vote:
Current Rating: 0/10 (0 votes)

Comments (Click to post)

Comments
Name:
Subject:
Website:
Message: 

Similar Articles (Based on Title)

*-dev Developers meeting at von - September 10, 2006
Olle has posted details of the developers meeting at VON.

*-dev Open Source Pavilion at AstriCon: Your project wanted - July 31, 2009
John Todd has posted a note to let people know that Digium will give you a free booth and passes to Astricon for an Open Source project.

*-Dev: pseudo realtime and load issue - August 25, 2005
Steven Critchfield has posted details of a patch to reduce the risk of running Asterisk in pseudo realtime mode.

*-Announce: New issue tracker for handling licensing issues for Asterisk, Zaptel and related projects - February 7, 2006
The Asterisk Development Team have posted details of a new issue tracker for Asterisk and Zaptel etc.

Update on FBI Issue - Important - December 9, 2008
John Todd has sent a detailed note to the Asterisk developers list regarding the recent security release. Please post this wherever you can.

Workflow Guidelines for Asterisk Open Source Issue Tracker - September 25, 2009
The purpose of this document is to briefly describe the various statuses an issue can be placed in, and what that status means. In addition, the simple workflow and transition between statuses will be discussed.

Testers Needed Issue 16965 DBGet response does not end with a Complete event - March 19, 2010
Ryan Bullock is looking for people to test a patch he has written to fix the DBGet Action.

New IP phone snom 190 addresses security in VoIP - September 19, 2004
With the snom 190, the Berlin company addresses recent concerns about security of VoIP calls and adds productivity features for the business user.

New Security List - January 24, 2005
Steve Szmidt has posted details on the Asterisk-Security list.

VoIP-forum.com: NIST report urges caution with VoIP security - January 28, 2005
Olle's site has posted a link to an article on VoIP security.

Cisco tries to degrade the internet by attempting the patenting of security holes - July 9, 2005
There was a security hole discovered recently in the MTU Discovery process of ICMP packets.

Voip-News-Net: VoIP Security Roundup - January 27, 2006
There is an article on VoIP News Net discussing a few of the latest VoIP security threads.

*-Announce: Asterisk 1.2.9 and Asterisk 1.0.11 Released - Security Fix - June 6, 2006
The Asterisk Development Team today released Asterisk 1.2.9 and Asterisk 1.0.11 to address a security vulnerability in the IAX2 channel driver (chan_iax2).

Asterisk 1.2.9.1 and 1.0.11.1 Released -- Security Fix - June 7, 2006
The Asterisk release today has been rereleased.


Original Content (C) 2004-2010 Matt Riddell
Back 5  Feed Add
to
Google Subscribe with Bloglines
Go to today

Icons by: FastIcon.com


AstriDevCon: October 29th, Washington DC
August 23, 2010 Average Vote: 10
John Todd has posted a note about the AstriDevCon conference which occurs within the Astricon conference.

Code Review: SRTP support for Asterisk
March 12, 2009 Average Vote: 10
Terry Wilson has moved his SRTP branch onto the Digium review board.

The Everything Asterisk Video Collection
August 5, 2010 Average Vote: 10
Steven Sokol has posted a blog entry on Asterisk Video Resources.

Voip-Forum: Lots of new articles
March 12, 2005 Average Vote: 10
Oej's Voip-Forum.com site has posted lots of new news articles while I've been away. Hopefully you found them via the asterisk-docs site. If not I've bookmarked them for you.

Interview with Mark Spencer
November 26, 2004 Average Vote: 9.9
We have managed to get an interview with Mark Spencer AKA Markster. Mark Spencer is the creator of Asterisk and by far the most active developer.

Asterisk and Kamailio realtime integration tutorial
May 24, 2010 Average Vote: 9.9
Daniel-Constantin Mierla has posted a link to a tutorial on integrating Asterisk and Kamailio using realtime.

Asterisk and Kamailio (openser) realtime integration
August 5, 2010 Average Vote: 9.8
Daniel-Constantin Mierla posted a writeup on combining Asterisk and Kamailio.

Asterisk IPv6 update
February 1, 2010 Average Vote: 9.8
Olle has posted an update on IPV6 in Asterisk and a link to a blog post of his.

Proposal for T.38 transparent gateway design in Asterisk
April 29, 2010 Average Vote: 9.8
Kevin Fleming has posted a proposed design for a transparent T.38 gateway for Asterisk:

Back to life
July 21, 2010 Average Vote: 9.8
Hey all - I am back online after some pretty big projects which have taken all my time. Will be updating the Asterisk news over the next few days.

Announcing Adhearsion 0.8.5
August 25, 2010 Average Vote: 9.8
Ben Klang has posted a note about the latest release of Adhearsion - a framework for developing Asterisk based solutions using Ruby.

app_swift v2.0 released
July 21, 2010 Average Vote: 9.8
Like a few of these news stories that I will be posting over the next couple of days this is a little old - hope it is not something you have already seen. This one is for a new version of the app_swift text-to-speech module for Asterisk 1.2, 1.4, and 1.6.

Monitoring Asterisk with Munin
January 7, 2010 Average Vote: 9.7
I had a few requests for these munin plugins after some discussion on one of the Asterisk lists and thought people might like them.

GUI changes from Trixbox, FreePBX, 2600hz, BlueBox
September 1, 2010 Average Vote: 9.7
Ok, bear with me on this one. If you understand all the ramifications, FreePBX has split to a new project called BlueBox contained within the 2600hz project. This obviously has implications for Trixbox that uses FreePBX to provide quite a bit of functionality.

Nerd Vittles: Finally... Installing Asterisk at Home on Your Windows PC
February 9, 2006 Average Vote: 9.7
Ward Mundy has posted details of a how to for installing Asterisk at Home on a windows machine without removing windows.


libpri 1.4.11.4 Now Available
September 3, 2010
The Asterisk Development Team has announced the release of libpri 1.4.11.4.

New CDR Stats Package
September 1, 2010
This one has been a long time coming. A new CDR stats package from Star2Billing to replace the 7 year old stalwart for viewing Asterisk call detail records.

GUI changes from Trixbox, FreePBX, 2600hz, BlueBox
September 1, 2010
Ok, bear with me on this one. If you understand all the ramifications, FreePBX has split to a new project called BlueBox contained within the 2600hz project. This obviously has implications for Trixbox that uses FreePBX to provide quite a bit of functionality.

RazorQuotePBP Asterisk Payment Module
August 31, 2010
RazorQuote has sent us a press release about the launch of RazorQuotePBP, a native Asterisk module that allows any Asterisk connected device to accept credit card payments.

CloudVox: Install an open source Asterisk phone app and get 250 dollars
August 30, 2010
CloudVox is running a competition for people to receive 250 dollars for writing up some documentation for Open Source applications on CloudVox - first in first served.

AstriCon approaches
August 25, 2010
John Todd has posted a note about the upcoming AstriCon conference in Washington, DC, and the innovation awards.

Announcing Adhearsion 0.8.5
August 25, 2010
Ben Klang has posted a note about the latest release of Adhearsion - a framework for developing Asterisk based solutions using Ruby.

Asterisk 1.8.0-beta4 Now Available
August 25, 2010
The Asterisk Development Team has announced the release of Asterisk 1.8.0-beta4.

AstriDevCon: October 29th, Washington DC
August 23, 2010
John Todd has posted a note about the AstriDevCon conference which occurs within the Astricon conference.

The XV Commandments of IVR
August 17, 2010
An update on the 15 tips for creating effective IVR systems by Allison Smith - the Voice of Asterisk.