Thu, 20 Jan 2011 21:35:00 -0400 The Asterisk Development Team has announced a release for the security issue described in AST-2011-001.
Due to a failed merge, Asterisk 1.8.2.1 which should have included the security fix did not. Asterisk 1.8.2.2 contains the the changes which should have been included in Asterisk 1.8.2.1.
This releases is available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/releases
The releases of Asterisk 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.2, 1.8.1.2, and 1.8.2.2 resolve an issue when forming an outgoing SIP request while in pedantic mode, which can cause a stack buffer to be made to overflow if supplied with carefully crafted caller ID information. The issue and resolution are described in the AST-2011-001 security advisory.
For more information about the details of this vulnerability, please read the security advisory AST-2011-001, which was released at the same time as this announcement.
For a full list of changes in the current release, please see the ChangeLog:
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.2.2
Security advisory AST-2011-001 is available at:
http://downloads.asterisk.org/pub/security/AST-2011-001.pdf
Thank you for your continued support of Asterisk!
Wednesday, February 16, 2011
Asterisk 1.8.2.2 Now Available (Security Release)
Monday, February 7, 2011
Asterisk Elastix Launches Security Module
As the fastest growing and most popular asterisk based PBX software, Elastix has now launched a security module for the community to help administrators to keep their installations more secured. From the version 2.0.4 and on, Elastix will count with this new module.

This module will be included in the distro, by default, and is part of a policy of the Elastix development department to keep new versions “secure by themselves”, and what will keep at minimum the use of additional infrastructure for security, like firewall equipments.
At first, this module will be launched with 3 components: an embedded firewall, an audit report and a week key detector; however, we expect to improve the functionality of this module in next versions.
“This is just the first version. We have many more ideas in mind for security so that in future we will include more and more functionality to this module” Says Edgar Landivar, CEO of PaloSanto Solutions, the company behind the Elastix product. “Many other IP-PBX products do not have similar tools so Elastix is an example to follow”.
The embedded firewall will block network services in order to expose only what’s necessary. It will also contain a set of suggested security policies that can be applied even for users without deep knowledge of firewalling.
“The firewall was a community suggestion that we decided to include and we are very satisfied with what we are releasing to the market” said Landivar.
On the other hand, the audit report will reveal details of logins to the Elastix web interface. This tool will be very useful for tracking unusual activity, including the internal network, allowing us to find the IP address that originated each access.
Finally the weak key detector is intended to alert the administrator if a password easy to “break” is found.
It is well known by many that some administrators often use predictable keys (also called weak) when creating their telephone extensions. This bad practice is a big problem if you decide to expose the computer to the Internet. With the weak key detector the Elastix server warns of this problem to the administrator and to take immediate corrective action.
The security module was released as a beta on January 6th, 2011 and can be downloaded along with the Elastix 2.0.4-beta version.
asterisk · Edgar LandÃvar · elastix · Elastix security module · firewall · IPPBX<< Breaking News: Industry 1st Interrupt Routing Adjustable Asterisk Cards ReleasedMore Than Two Million Downloads of Asterisk in 2010 >>