Tuesday, June 26, 2012

Asterisk 10.5.1 Now Available

The Asterisk Development Team has announced a security release for Asterisk 10.
This security release is released as version 10.5.1.
The release is available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk/releases
The release of Asterisk 10.5.1 resolves the following issue:
  • A remotely exploitable crash vulnerability was found in the Skinny (SCCP)
    Channel driver. When an SCCP client sends an Off Hook message, followed by
    a Key Pad Button Message, a structure that was previously set to NULL is
    dereferenced. This allows remote authenticated connections the ability to
    cause a crash in the server, denying services to legitimate users.

No comments:

Post a Comment