I'd like to thank everyone on this thread for their responsiveness and thoughtful comments.
As a strong believer in responsible vulnerability disclosure I was a bit worried at first, but I now feel confident as I learned it's being worked on, people care, and posting to official vulnerability reporting entities is being considered. I'd also like to point out that the entire project is a huge win in terms of security compared to typical proprietary PBX solutions :) Kind regards, -- leander - [EMAIL PROTECTED] _______________________________________________ --Bandwidth and Colocation provided by Easynews.com -- Asterisk-Security mailing list To UNSUBSCRIBE or update options visit: http://lists.digium.com/mailman/listinfo/asterisk-security