[asterisk-announce] AST-2019-006: SIP request can change address of a SIP peer.

2019-11-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-006 ProductAsterisk SummarySIP request can change address of a SIP peer. Nature of Advisory Denial of Service

[asterisk-announce] AST-2019-007: AMI user could execute system commands.

2019-11-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-007 ProductAsterisk SummaryAMI user could execute system commands. Nature of Advisory Remote Code Execution

[asterisk-announce] Asterisk 13.29.2, 16.6.2, 17.0.1 and 13.21-cert5 Now Available (Security)

2019-11-21 Thread Asterisk Development Team
The Asterisk Development Team would like to announce security releases for Asterisk 13, 16 and 17, and Certified Asterisk 13.21. The available releases are released as versions 13.29.2, 16.6.2, 17.0.1 and 13.21-cert5. These releases are available for immediate download at

[asterisk-announce] AST-2019-008: Re-invite with T.38 and malformed SDP causes crash.

2019-11-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - ProductAsterisk SummaryRe-invite with T.38 and malformed SDP causes crash. Nature of Advisory Remote Crash