<div dir="ltr"><div><div>The Asterisk Development Team has announced security releases for Certified</div><div>Asterisk 13.1 and Asterisk 13. The available security releases are released as<br>versions 13.1-cert5, and 13.8.1.</div><div><br></div><div>These releases are available for immediate download at</div><div><a href="http://downloads.asterisk.org/pub/telephony/asterisk/releases" target="_blank">http://downloads.asterisk.org/pub/telephony/asterisk/releases</a></div><div><br></div><div>The release of these versions resolves the following security vulnerabilities:</div><div><br></div><div>* AST-2016-004: Long contact URIs in REGISTER requests can crash Asterisk<br></div><br>Â Asterisk may crash when processing an incoming REGISTER request if that<br>Â REGISTER contains a Contact header with a lengthy URI. This crash will only<br>Â happen for requests that pass authentication. Unauthenticated REGISTER<br>Â requests will not result in a crash occurring.<br><br><div>* AST-2016-005: TCP denial of service in PJProject<br><br>Â PJProject has a limit on the number of TCP connections that it can accept.<br>Â Furthermore, PJProject does not close TCP connections it accepts. By default,<br>Â this value is approximately 60. An attacker can deplete the number of allowed<br>Â TCP connections by opening TCP connections and sending no data to Asterisk.<br><br>Â If PJProject has been compiled in debug mode, then once the number of allowed<br>Â TCP connections has been depleted, the next attempted TCP connection to<br>Â Asterisk will crash due to an assertion in PJProject. If PJProject has not<br>Â been compiled in debug mode, then any further TCP connection attempts will be<br>Â rejected. This makes Asterisk unable to process TCP SIP traffic.<br></div><br><div>For a full list of changes in the current releases, please see the ChangeLogs:</div><div><br></div><div><a href="http://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/ChangeLog-certified-13.1-cert5" target="_blank">http://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/ChangeLog-certified-13.1-cert5</a></div><div><a href="http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-13.8.1" target="_blank">http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-13.8.1</a></div><div><br></div><div>The security advisories are available at:</div><div><br></div><div>Â * <a href="http://downloads.asterisk.org/pub/security/AST-2016-004.pdf" target="_blank">http://downloads.asterisk.org/pub/security/AST-2016-004.pdf</a></div><div>Â * <a href="http://downloads.asterisk.org/pub/security/AST-2016-005.pdf" target="_blank">http://downloads.asterisk.org/pub/security/AST-2016-005.pdf</a></div><div><br></div><div>Thank you for your continued support of Asterisk!</div></div></div>