Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Open source Asterisk IP PBX needs patches to fix flaws

Vulnerabilities can lead to crashes, unathenticated calls
By Tim Greene , Network World , 03/21/2008
  • Share/Email
  • Comment
  • Print

Businesses using open-source Asterisk-based IP PBXs should check whether to update the software version they are using in order to rid themselves of vulnerabilities that could compromise the systems.

Attackers can exploit the two vulnerabilities to launch buffer-overflow attacks, hijack calls and make unauthenticated calls.

The Asterisk Development Team has issued patches for four versions of Asterisk affected by vulnerabilities.

No actual exploits based on the vulnerabilities has been reported.

Open source Asterisk is free for download and is also used as the basis for commercial PBXs and peripheral software such as call centers. The creators of this PBX sell a commercial version under the name Digium.

  • Share/Email
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed