Friday, December 07, 2007

Asterisk 1.4.15 and 1.2.25 To Fix SQL Security Issues

The Asterisk.org development team has released Asterisk versions 1.4.15 and 1.2.25. These releases contain two fixes for security issues.

Security Issue One
* This is a SQL injection vulnerability in the res_config_pgsql module. Default installations of Asterisk are not affected. However, any system using the Postgres Realtime Engine may be remotely exploitable. This issue only affects Asterisk 1.4, as this module was not in Asterisk 1.2.

Security Issue Two
* This is another SQL injection vulnerability. The input for the ANI and DNIS fields were not properly escaped. Default installations of Asterisk are not vulnerable. However, systems that use the Postgres CDR logging module may be remotely exploitable. This issue affects both Asterisk 1.2 and 1.4.

Both releases are available on http://downloads.digium.com.

0 comments:

Blog Widget by LinkWithin