Asterisk Security Vulnerability in SIP Channel Driver

Digium securityOn December 26th, Grey VoIP reported a security hole in Asterisk - an Asterisk SIP Channel Driver BYE Message Denial of Service (DoS) vulnerability. The vulnerability could allow a remote user to send a specially crafted BYE message using the 'BYE with Also' transfer method to trigger a NULL pointer error cause the target service to crash. In just a week, Digium, the founders of the open source Asterisk platform, released an update to fix the problem.

Every IP-PBX will have its share of bugs and security holes, I get Cisco advisories all the time, so I wasn't too concerned when I heard about this security vulnerability in Asterisk. But what amazes me is the fast turnaround to fix it - and over the major holidays no less!

Kudos to the Digium team and/or the open source community which were quick to react to this security issue! I'd be curious if it was the open source community that issued the patch or Digium. I'll fire off an email to Mark Spencer and see if he can give some insights.

Update (10:16am): Mark Spencer got back to me in 5 minutes. Here's his response
"The issue was reported as simply a bug on the issue tracker, but Digium's development team recognized this was a security vulnerability and provided the fix, as well as testing each branch of Asterisk and backporting the fix to all versions of Asterisk that were affected (all 1.4 based). Thanks for your interest!"

Even though the open source community helps in the development of Asterisk, this certainly goes to show the importance of Digium and their hired programmers to update Asterisk. Again, kudos to the Digium team in fixing this so quickly.
| 1 Comment | 0 TrackBacks

Listed below are links to sites that reference Asterisk Security Vulnerability in SIP Channel Driver:

Asterisk Security Vulnerability in SIP Channel Driver TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/34486

1 Comment

Not bad for free!

Leave a comment

Recent Activity

Saturday

  • Tom Keating tweeted, "Spending 4th of July with in-laws on their lake-side house. Coming soon - fireworks!"

Friday

  • Tom Keating queued Star Trek
  • Tom Keating queued Stardust
  • Tom Keating queued The Fountain

Thursday

More...

Recent Comments

  • ctjames: Yes , I've tried several times by using Cydia installed read more
  • http://openid.aol.com/drdaraban: Yes, I confirm antonioj's comment, both skype and the app read more
  • cmytroops: I was browsing the net and cam across a great read more
  • mike: Sorry if this is off topic but I’m thinking of read more
  • @NumberGarage: Our military service men and women should be driving new read more
  • https://www.google.com/accounts/o8/id?id=AItOawlacBYIyCFI8mz5HS_pdsnSDV1wLz6Vgc8: We have implemented over 50 VoIP systems in the last read more
  • Theo Barton: Its a good phone. I have had a lot of read more
  • https://me.yahoo.com/a/ea7WMvNu2Mlud7dBwQPAAus9JCfo9qE-#27391: I don't want to go through all the problems, I read more
  • Claudio G.: I contacted these folks via e-mail recently (June 2009)and they read more
  • Kinjudah De- Morgan: I am using a strong satelite receiver and a Gateway read more

Subscribe to Blog

    View my Microsoft MVP Profile:

Blogroll

Entry Archives

Around TMCnet Blogs

  • Communications and Technology Blog - Tehrani.com:
    Problems at Joost
  • On Rad's Radar?:
    USF and Rural Reform
  • VoIP & Gadgets Blog:
    Worst Google News Headline Ever! - No public viewing
  • Communications and Technology Blog - Tehrani.com:
    Heading to Rhode Island
  • First Coffee:
    SugarCRM Studied, Broadband 'Crucial,' EGain, OOCOSPI, NetSuite's Zander
  • On Rad's Radar?:
    Bells Giving Up on Landlines?
  • The Readerboard:
    Tougher Actions To Save Telemarketing
  • VoIP & Gadgets Blog:
    eBuddy for iPhone Supports Push Notifications
  • Latest Whitepapers

    TMCnet Videos