CORRECTED Asterisk Release Certified-18.9-cert6

Home » Asterisk Users » CORRECTED Asterisk Release Certified-18.9-cert6
Asterisk Users No Comments

The earlier release announcement should NOT have had any User or Upgrade notes.

The Asterisk Development Team would like to announce security release Certified Asterisk 18.9-cert6.

The release artifacts are available for immediate download at https://github.com/asterisk/asterisk/releases/tag/certified-18.9-cert6
and https://downloads.asterisk.org/pub/telephony/certified-asterisk

The following security advisories were resolved in this release:
– [Path traversal via AMI GetConfig allows access to outside files](
https://github.com/asterisk/asterisk/security/advisories/GHSA-8857-hfmw-vg8f
)
– [Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation](
https://github.com/asterisk/asterisk/security/advisories/GHSA-hxj9-xwr8-w8pq
)
– [PJSIP logging allows attacker to inject fake Asterisk log entries ](
https://github.com/asterisk/asterisk/security/advisories/GHSA-5743-x3p5-3rg7
)
– [PJSIP_HEADER dialplan function can overwrite memory/cause crash when using ‘update’](
https://github.com/asterisk/asterisk/security/advisories/GHSA-98rc-4j27-74hh
)

Change Log for Release asterisk-certified-18.9-cert6
=======================================
Links:
————————————–