[asterisk-dev] Asterisk 13.38.1, 16.15.1, 17.9.1 and 18.1.1 Now Available (Security)

Asterisk Development Team asteriskteam at digium.com
Tue Dec 22 17:07:46 CST 2020


The Asterisk Development Team would like to announce security releases for
Asterisk 13, 16, 17 and 18. The available releases are released as versions
13.38.1, 16.15.1, 17.9.1 and 18.1.1.

These releases are available for immediate download at

https://downloads.asterisk.org/pub/telephony/asterisk/releases

The following security vulnerabilities were resolved in these versions:

* AST-2020-003: Remote crash in res_pjsip_diversion
  A crash can occur in Asterisk when a SIP message is received that has a
  History-Info header, which contains a tel-uri.

* AST-2020-004: Remote crash in res_pjsip_diversion
  A crash can occur in Asterisk when a SIP 181 response is received that has a
  Diversion header, which contains a tel-uri.

For a full list of changes in the current releases, please see the ChangeLogs:

https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-13.38.1
https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-16.15.1
https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-17.9.1
https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-18.1.1

The security advisories are available at:

https://downloads.asterisk.org/pub/security/AST-2020-003.pdf
https://downloads.asterisk.org/pub/security/AST-2020-004.pdf

Thank you for your continued support of Asterisk!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.digium.com/pipermail/asterisk-dev/attachments/20201222/d60359ec/attachment.html>


More information about the asterisk-dev mailing list