« Back to the top page
IDG News Service

Open-source Asterisk IP PBX needs patches to fix flaws

Tim Greene, Networld World03.21.2008
Tags
Comments 0
Like the story? Get Alerts of big news events. Enter your email address

Businesses using open-source Asterisk-based IP PBXs should check whether to update the software version they are using in order to rid themselves of vulnerabilities that could compromise the systems.

Exploiting the two vulnerabilities can lead to buffer overflow attacks, hijacked calls and allow attackers to make unauthenticated calls.

The Asterisk Development Team has issued patches for four versions of Asterisk affected by vulnerabilities.

No actual exploits based on the vulnerabilities has been reported.

Open source Asterisk is free for download and is also used as the basis for commercial PBXs and peripheral software such as call centers. The creators of this PBX sell a commercial version under the name Digium.

Reprinted with permission from Networld World. Story copyright 2008 Networld World Inc. All rights reserved.

Post new comment

The content of this field is kept private and will not be shown publicly.
Respectful debate is welcome, but comments that are defamatory, indecent, abusive, or in violation of any law will be removed.