The Asterisk Development Team would like to announce security releases for Asterisk 13, 16, 17 and 18. The available releases are released as versions 13.38.1, 16.15.1, 17.9.1 and 18.1.1.
These releases are available for immediate download at
The following security vulnerabilities were resolved in these versions:
-
AST-2020-003: Remote crash in res_pjsip_diversion
A crash can occur in Asterisk when a SIP message is received that has a
History-Info header, which contains a tel-uri. -
AST-2020-004: Remote crash in res_pjsip_diversion
A crash can occur in Asterisk when a SIP 181 response is received that has a
Diversion header, which contains a tel-uri.
For a full list of changes in the current releases, please see the ChangeLogs:
ChangeLog-13.38.1
ChangeLog-16.15.1
ChangeLog-17.9.1
ChangeLog-18.1.1
The security advisories are available at:
AST-2020-003.pdf
AST-2020-004.pdf
Thank you for your continued support of Asterisk!