Bug 27618 - Asterisk 13.37.1, 16.14.1, 17.8.1, 18.0.1 and 16.8-cert5 Now Available (Security)
Summary: Asterisk 13.37.1, 16.14.1, 17.8.1, 18.0.1 and 16.8-cert5 Now Available (Secur...
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact:
URL: https://www.asterisk.org/asterisk-new...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-11-17 01:04 CET by Zombie Ryushu
Modified: 2020-11-17 16:03 CET (History)
2 users (show)

See Also:
Source RPM: asterisk
CVE:
Status comment:


Attachments

Description Zombie Ryushu 2020-11-17 01:04:24 CET
The following security vulnerabilities were resolved in these versions:

        AST-2020-001: Remote crash in res_pjsip_session
        Upon receiving a new SIP Invite, Asterisk did not return the created dialog
        locked or referenced.

 

    AST-2020-002: Outbound INVITE loop on challenge with different nonce.
    If Asterisk is challenged on an outbound INVITE and the nonce is changed in
    each response, Asterisk will continually send INVITEs in a loop. This causes
    Asterisk to consume more and more memory since the transaction will never
    terminate (even if the call is hung up), ultimately leading to a restart or
    shutdown of Asterisk. Outbound authentication must be configured on the
    endpoint for this to occur.

For a full list of changes in the current releases, please see the ChangeLogs:
Comment 1 Aurelien Oudelet 2020-11-17 10:36:52 CET
I really can't find an asterisk package in our repo.

CC: (none) => ouaurelien
Ever confirmed: 1 => 0
Status: NEW => UNCONFIRMED

Comment 2 David Walser 2020-11-17 15:49:57 CET
Indeed we haven't packaged it in years.

CC'ing a packager who's looking to possibly bring it back.

Also noting that it apparently has a mailing list:
http://lists.digium.com/mailman/listinfo/asterisk-announce

Status: UNCONFIRMED => RESOLVED
CC: (none) => alien
Resolution: (none) => INVALID

Comment 3 Zombie Ryushu 2020-11-17 15:55:57 CET
Pull from Rosa then.
Comment 4 David Walser 2020-11-17 16:03:14 CET
No.

Note You need to log in before you can comment on or make changes to this bug.