<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.theindustrystandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The Industry Standard - Open-source Asterisk IP PBX needs patches to fix flaws - Comments</title>
 <link>http://www.theindustrystandard.com/news/2008/03/21/open-source-asterisk-ip-pbx-needs-patches-fix-flaws</link>
 <description>Comments for &quot;Open-source Asterisk IP PBX needs patches to fix flaws&quot;</description>
 <language>en</language>
<item>
 <title>Open-source Asterisk IP PBX needs patches to fix flaws</title>
 <link>http://www.theindustrystandard.com/news/2008/03/21/open-source-asterisk-ip-pbx-needs-patches-fix-flaws</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;Businesses using open-source &lt;a href=&quot;http://www.networkworld.com/news/2008/012408-special-focus.html&quot; rel=&quot;nofollow&quot;&gt;Asterisk-based&lt;/a&gt; IP PBXs should check whether to update the software version they are using in order to rid themselves of vulnerabilities that could compromise the systems.&lt;/p&gt;
&lt;p&gt;Exploiting the two vulnerabilities can lead to buffer overflow attacks, hijacked calls and allow attackers to make unauthenticated calls.&lt;/p&gt;
&lt;p&gt;The Asterisk Development Team has issued patches for &lt;a href=&quot;http://www.asterisk.org/node/48466&quot; rel=&quot;nofollow&quot;&gt;four versions&lt;/a&gt; of Asterisk affected by vulnerabilities.&lt;/p&gt;
&lt;p&gt;No actual exploits based on the vulnerabilities has been reported.&lt;/p&gt;
&lt;p&gt;Open source Asterisk is free for download and is also used as the basis for commercial PBXs and peripheral software such as call centers. The creators of this PBX sell a commercial version under the name &lt;a href=&quot;http://www.networkworld.com/news/2008/021108-digium-asterisk-warranty.html &quot; rel=&quot;nofollow&quot;&gt;Digium&lt;/a&gt;.&lt;/p&gt;
</description>
 <comments>http://www.theindustrystandard.com/news/2008/03/21/open-source-asterisk-ip-pbx-needs-patches-fix-flaws#comments</comments>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/2487">Exploits and vulnerabilities</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1402">IDGNS</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1531">Internet</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1615">Open source</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1428">Security</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/1520">Software</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.theindustrystandard.com/taxonomy/term/98">Breaking News</category>
 <pubDate>Fri, 21 Mar 2008 10:32:19 -0700</pubDate>
 <dc:creator>IDG News Service</dc:creator>
 <guid isPermaLink="false">103570 at http://www.theindustrystandard.com</guid>
</item>
</channel>
</rss>
