Posts Tagged 1.6.2
Asterisk 1.6.0.22, Asterisk 1.6.1.14, Asterisk 1.6.2.2 Released
Posted by admin in Asterisk Security Advisories, Releases, Security Advisories, asterisk, sip, t.38 on February 2, 2010
The Asterisk Development Team has announced security releases for Asterisk as the following versions:
These releases are available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/
The releases of Asterisk 1.6.0.22, 1.6.1.14, and 1.6.2.2 include the fix described in security advisory AST-2010-001.
The issue is that an attacker attempting to negotiate T.38 over SIP can remotely crash Asterisk by modifying the FaxMaxDatagram field of the SDP to contain either a negative or exceptionally large value. The same crash will occur when the FaxMaxDatagram field is omitted from the SDP, as well.
For more information about the details of this vulnerability, please read the security advisory AST-2010-001, which was released at the same time as this announcement.
For a full list of changes in the current releases, please see the ChangeLog:
- http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.0.22
- http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.1.14
- http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.2
Security advisory AST-2010-001 is available at:
http://asterisk.net.ru/en/2010/02/03/asterisk-security-advisory-ast-2010-001-t-38-remote-crash-vulnerability/
Thank you for your continued support of Asterisk!
Asterisk 1.6.2.1 Now Available
The Asterisk Development Team has announced the release of Asterisk 1.6.2.1.
This release is available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/
The release of Asterisk 1.6.2.1 resolved several issues reported by the community, and would have not been possible without your participation. Thank you!
- CLI ‘queue show’ formatting fix.
(Closes issue #16078. Reported by RoadKill. Tested by dvossel. Patched by ppyy.) - Fix misreverting from 177158.
(Closes issue #15725. Reported, Tested by shanermn. Patched by dimas.) - Fixes subscriptions being lost after ‘module reload’.
(Closes issue #16093. Reported by jlaroff. Patched by dvossel.) - app_queue segfaults if realtime field uniqueid is NULL
(Closes issue #16385. Reported, Tested, Patched by haakon.) - Fix to Monitor which previously assumed the file to write to did not contain pathing.
(Closes issue #16377, #16376. Reported by bcnit. Patched by dant.
A summary of changes in this release can be found in the release summary:
http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-1.6.2.1-summary.txt
For a full list of changes in this releases, please see the ChangeLog:
http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.1
Thank you for your continued support of Asterisk!
Read the rest of this entry »
Asterisk 1.4.29-rc1, Asterisk 1.6.0.21-rc1, Asterisk 1.6.1.13-rc1, Asterisk 1.6.2.1-rc1 Released
Posted by admin in Release Candidates, asterisk on January 11, 2010
The Asterisk Development Team has announced release candidates (RC1) for Asterisk versions 1.4.29, 1.6.0.21, 1.6.1.13, and 1.6.2.1. These release candidates are available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/
The release candidates address issues that were reported by the community and resolved since the last round of bug fix releases.
For a full list of changes in the current release candidates, please see the ChangeLogs:
http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.4.29-rc1
http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.0.21-rc1
http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.1.13-rc1
http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.1-rc1
For a summary of the issues found in these release candidates, please see the summary files:
http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-1.4.29-rc1-summary.html
http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-1.6.0.21-rc1-summary.html
http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-1.6.1.13-rc1-summary.html
http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-1.6.2.1-rc1-summary.html
Issues found in any of these release candidates should be reported to the Asterisk issue tracker at http://issues.asterisk.org
Thank you for your continued support of Asterisk!
Read the rest of this entry »
Asterisk 1.4.27-rc3, Asterisk 1.6.0.18-rc1, Asterisk 1.6.1.10-rc1, and Asterisk 1.6.2.0-rc4 released
The Asterisk Development Team has announced the next set of Asterisk release candidates for versions 1.4.27, 1.6.0.18, 1.6.1.10, and 1.6.2.0. These release candidates are available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/
The release candidates address issues that were reported by the community and resolved since the last round of bug fix releases. The currently available release candidate versions are 1.4.27-rc3, 1.6.0.18-rc1, 1.6.1.10-rc1, and 1.6.2.0-rc4.
Please note that that 1.6.0.18-rc1 is a continuation of bug fixes since 1.6.0.16-rc2. 1.6.0.17 was released as a security release based on 1.6.0.15.
Asterisk 1.6.1.10-rc1 is a continuation of bug fixes since 1.6.1.7-rc2 as versions 1.6.1.8 and 1.6.1.9 were security releases for the 1.6.1 branch.
These release candidates include bug fixes along with the recently released security fixes.
Read the rest of this entry »
Asterisk 1.6.0.11-rc2, 1.6.1.2, 1.6.1.3-rc1, and 1.6.2.0-beta4 Release Announcement
Posted by admin in Asterisk Security Advisories, Release Candidates, Releases, Security Advisories, asterisk, t.38 on August 3, 2009
The Asterisk Development Team is pleased to announce the the second release candidate of 1.6.0.11, the release of 1.6.1.2, the first release candidate of 1.6.1.3, and the fourth beta of 1.6.2.0. These releases are available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/.
The release of 1.6.1.2 fixes a remote crash security vulnerability in the RTP stack. The related security advisory AST-2009-004 has been released along with this announcement. Please read that advisory for more information.
The release candidates and betas, in addition to other fixes, contain a major re-work of the T.38 support in Asterisk. If you’ve been having trouble with T.38 in the 1.6 series, you are strongly encouraged to try one of these release candidates to determine if these changes fixed your T.38 issues.
Asterisk-Addons 1.4.9-rc1, 1.6.0.3-rc2, 1.6.1.1-rc2, and 1.6.2.0-rc1 released
Posted by admin in asterisk addons on July 14, 2009
The Asterisk Development Team has announced several Asterisk-Addons release candidates, including Asterisk-Addons 1.4.9-rc1, 1.6.0.3-rc2, 1.6.1.1-rc2, and 1.6.2.0-rc1. The release candidates are available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/
These releases are an incremental release after some community reported issues were resolved, primarily in the MySQL and chan_mobile realms.
- Using chan_local with chan_mobile (issue #15299, affects all 1.6.x versions)
- Don’t reset a reconnect time unless a reconnect really occurred (issue #15375, affects all versions)
For a full list of changes in this release candidate, please see the ChangeLogs:
http://svn.asterisk.org/svn/asterisk-addons/tags/1.4.9-rc1/ChangeLog
http://svn.asterisk.org/svn/asterisk-addons/tags/1.4.9-rc1/ChangeLog
http://svn.asterisk.org/svn/asterisk-addons/tags/1.6.1.1-rc2/ChangeLog
http://svn.asterisk.org/svn/asterisk-addons/tags/1.6.2.0-rc1/ChangeLog
Issues found in any release candidate can be reported at:
https://issues.asterisk.org
Thank you for your continued support of Asterisk!
Asterisk 1.6.2.0-beta3 released
The Asterisk Development Team is pleased to announce the third beta of Asterisk 1.6.2.0. Asterisk-1.6.2.0-beta3 is available for immediate download at http://downloads.digium.com/pub/asterisk/
This is an incremental release of the 1.6.2.0 branch as the previous beta was released just over a month ago, and many issues have been resolved since then.
Included in this release are the following issues reported by the community:
- Update spiral support in trunk and 1.6.x branches to match what is in 1.4 (related to issue #13630).
- Fix RFC2833 issues with DTMF getting duplicated and with duration wrapping over (issue #14815).
- Fix a bug where the codecs of the called party leg were not properly sent back to the call leg when reinvited (issue #13569).
- Fix broken attended transfers (issue #15183).
- Add flags to chanspy audiohook so that audio stays in sync (issue #13745).
- Resolve issues with choppy sound when using res_timing_pthread (issue #14412)
Additionally, an update to chan_iax2 related to issue AST-2009-001 is included in this beta release. For more information, see:
http://downloads.asterisk.org/pub/security/AST-2009-001.html
For a full list of changes in this beta, please see the ChangeLog:
http://svn.digium.com/svn/asterisk/tags/1.6.2.0-beta3/ChangeLog
You can get more information about the new features and various changes in Asterisk 1.6.2.0 at:
http://svn.digium.com/svn/asterisk/tags/1.6.2.0-beta3/CHANGES
And if you’re upgrading from previous versions of Asterisk see this file:
http://svn.digium.com/svn/asterisk/tags/1.6.2.0-beta3/UPGRADE.txt
Issues discovered in testing of this beta can be reported at http://issues.asterisk.org
Thank you for your continued support of Asterisk!
Asterisk 1.6.0.7-rc2, 1.6.1.0-rc3, 1.6.2.0-beta1 & Asterisk-Addons 1.6.0.2-rc1, 1.6.1.0-rc3 Released
Posted by admin in asterisk, asterisk addons on March 20, 2009
The Asterisk.org development team is pleased to announced the release of Asterisk release candidates 1.6.0.7-rc2, 1.6.1.0-rc3, and beta release 1.6.2.0-beta1. Additionally, new release candidates of Asterisk-Addons 1.6.0.2-rc1 and 1.6.1.0-rc3 have been created. Note that the 1.6.1 series of Asterisk-Addons is compatible with both Asterisk 1.6.1 and 1.6.2 branches.
These releases are available for immediate download from http://downloads.digium.com/.
These Asterisk releases improve compatibility with T.38 switchovers internally; fixes an issue with Asterisk using poll() on OSX systems when it should not; allows chan_h323 to be built against both OpenH323 and H323Plus libraries
(while simplifying the build process); and improve behavior of ast_answer() which was problematic for T.38 re-INVITES and other sorts of channel operations. Additionally, other bugs have also been resolved in these release
candidates.
The Asterisk-Addons release candidates fix a few minor issues since the last set of release candidates.
The first beta release of the Asterisk 1.6.2 series is now available. You can get more information about the new features and various changes in this release at:
http://svn.digium.com/view/asterisk/tags/1.6.2.0-beta1/CHANGES?view=co
And if you’re upgrading from previous versions of Asterisk see this file:
http://svn.digium.com/view/asterisk/tags/1.6.2.0-beta1/UPGRADE.txt?view=co
ChangeLogs for the various releases candidates and beta are available at:
http://svn.digium.com/view/asterisk/tags/1.6.0.7-rc2/ChangeLog?view=co
http://svn.digium.com/view/asterisk/tags/1.6.1.0-rc3/ChangeLog?view=co
http://svn.digium.com/view/asterisk/tags/1.6.2.0-beta1/ChangeLog?view=co
http://svn.digium.com/view/asterisk-addons/tags/1.6.0.2-rc1/ChangeLog?view=co
http://svn.digium.com/view/asterisk-addons/tags/1.6.1.0-rc3/ChangeLog?view=co
Issues discovered in testing of these release candidates and beta can be reported at http://bugs.digium.com.
Thank you for your continued support of Asterisk!
