Hi all

I see no annocement in this list yet, so I'll post my own. Basically
untested copy&paste.

Asterisk 1.4.2:

- a fix for a SIP channel driver remote DoS vulnerability
  (http://bugs.digium.com/view.php?id=9313 , fixed in rev. 59037 )

Asterisk 1.4.2 and Asterisk 1.2.17:

- a fix for a SIP channel driver remote DoS vulnerability discovered
  by INRIA Lorraine
  (http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html )

Thus the update is highly recommended for all users of Asterisk 1.4 with 
the SIP channel driver loaded and connected to an untrusted network.

Sources:
http://asterisk.org/node/48339
http://asterisk.org/node/48338

-- 
               Tzafrir Cohen       
icq#16849755                    jabber:[EMAIL PROTECTED]
+972-50-7952406           mailto:[EMAIL PROTECTED]       
http://www.xorcom.com  iax:[EMAIL PROTECTED]/tzafrir
_______________________________________________
--Bandwidth and Colocation provided by Easynews.com --

Asterisk-Security mailing list
To UNSUBSCRIBE or update options visit:
   http://lists.digium.com/mailman/listinfo/asterisk-security

Reply via email to