[Asterisk-Dev] NEW Asterisk Security vulnerability report ...

Peter Grace pgrace at fierymoon.com
Wed Sep 17 13:42:18 MST 2003


 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Kind of along these lines, are there specific reasons why
asterisk has to run as root?  It gives me the
heeby-jeebies.  

Pete

- -----Original Message-----
From: asterisk-dev-admin at lists.digium.com
[mailto:asterisk-dev-admin at lists.digium.com] On Behalf Of
Lubomir Christov
Sent: Wednesday, September 17, 2003 9:16 AM
To: asterisk-dev at lists.digium.com;
asterisk-users at lists.digium.com
Subject: [Asterisk-Dev] NEW Asterisk Security vulnerability
report ...


Hello,

There is a new asterisk vulnerability report at this
address:

http://www.securiteam.com/unixfocus/5HP0H1PB5S.html

This is the second security report regarding asterisk for 8
days 
(http://www.securiteam.com/securitynews/5LP0720B5G.html)

Both fixes was reported and fixed silently.

My question is: Is it possible in the future such a
security problems to 
be reported in this mailing list or some other security
related list?

Lubo


_______________________________________________
Asterisk-Dev mailing list
Asterisk-Dev at lists.digium.com
http://lists.digium.com/mailman/listinfo/asterisk-dev

- ---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.518 / Virus Database: 316 - Release Date:
9/11/2003
 

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBP2jGsNW8rcEEsO4aEQLzNgCfZp71uKEHuupVwqO7VlkRte9paOkAn1Pb
lF6b94wjdDj+ne6LK+9JbS62
=t59M
-----END PGP SIGNATURE-----

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.518 / Virus Database: 316 - Release Date: 9/11/2003




More information about the asterisk-dev mailing list