mirror of
https://github.com/asterisk/asterisk.git
synced 2025-09-02 11:06:31 +00:00
79 lines
3.5 KiB
HTML
79 lines
3.5 KiB
HTML
<html><head><title>ChangeLog for asterisk-certified-20.7-cert7</title></head><body>
|
|
<h2>Change Log for Release asterisk-certified-20.7-cert7</h2>
|
|
<h3>Links:</h3>
|
|
<ul>
|
|
<li><a href="https://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/ChangeLog-certified-20.7-cert7.html">Full ChangeLog</a> </li>
|
|
<li><a href="https://github.com/asterisk/asterisk/compare/certified-20.7-cert6...certified-20.7-cert7">GitHub Diff</a> </li>
|
|
<li><a href="https://downloads.asterisk.org/pub/telephony/certified-asterisk/asterisk-certified-20.7-cert7.tar.gz">Tarball</a> </li>
|
|
<li><a href="https://downloads.asterisk.org/pub/telephony/certified-asterisk">Downloads</a> </li>
|
|
</ul>
|
|
<h3>Summary:</h3>
|
|
<ul>
|
|
<li>Commits: 2</li>
|
|
<li>Commit Authors: 2</li>
|
|
<li>Issues Resolved: 0</li>
|
|
<li>Security Advisories Resolved: 2</li>
|
|
<li><a href="https://github.com/asterisk/asterisk/security/advisories/GHSA-mrq5-74j5-f5cr">GHSA-mrq5-74j5-f5cr</a>: Remote DoS and possible RCE in asterisk/res/res_stir_shaken/verification.c</li>
|
|
<li><a href="https://github.com/asterisk/asterisk/security/advisories/GHSA-v9q8-9j8m-5xwp">GHSA-v9q8-9j8m-5xwp</a>: Uncontrolled Search-Path Element in safe_asterisk script may allow local privilege escalation.</li>
|
|
</ul>
|
|
<h3>User Notes:</h3>
|
|
<h3>Upgrade Notes:</h3>
|
|
<ul>
|
|
<li>
|
|
<h4>safe_asterisk: Add ownership checks for /etc/asterisk/startup.d and its files.</h4>
|
|
The safe_asterisk script now checks that, if it was run by the
|
|
root user, the /etc/asterisk/startup.d directory and all the files it contains
|
|
are owned by root. If the checks fail, safe_asterisk will exit with an error
|
|
and Asterisk will not be started. Additionally, the default logging
|
|
destination is now stderr instead of tty "9" which probably won't exist
|
|
in modern systems.</li>
|
|
</ul>
|
|
<h3>Developer Notes:</h3>
|
|
<h3>Commit Authors:</h3>
|
|
<ul>
|
|
<li>George Joseph: (1)</li>
|
|
<li>ThatTotallyRealMyth: (1)</li>
|
|
</ul>
|
|
<h2>Issue and Commit Detail:</h2>
|
|
<h3>Closed Issues:</h3>
|
|
<ul>
|
|
<li>!GHSA-mrq5-74j5-f5cr: Remote DoS and possible RCE in asterisk/res/res_stir_shaken/verification.c</li>
|
|
<li>!GHSA-v9q8-9j8m-5xwp: Uncontrolled Search-Path Element in safe_asterisk script may allow local privilege escalation.</li>
|
|
</ul>
|
|
<h3>Commits By Author:</h3>
|
|
<ul>
|
|
<li>
|
|
<h4>George Joseph (1):</h4>
|
|
</li>
|
|
<li>
|
|
<p>res_stir_shaken: Test for missing semicolon in Identity header.</p>
|
|
</li>
|
|
<li>
|
|
<h4>ThatTotallyRealMyth (1):</h4>
|
|
</li>
|
|
<li>safe_asterisk: Add ownership checks for /etc/asterisk/startup.d and its files.</li>
|
|
</ul>
|
|
<h3>Commit List:</h3>
|
|
<ul>
|
|
<li>safe_asterisk: Add ownership checks for /etc/asterisk/startup.d and its files.</li>
|
|
<li>res_stir_shaken: Test for missing semicolon in Identity header.</li>
|
|
</ul>
|
|
<h3>Commit Details:</h3>
|
|
<h4>safe_asterisk: Add ownership checks for /etc/asterisk/startup.d and its files.</h4>
|
|
<p>Author: ThatTotallyRealMyth
|
|
Date: 2025-06-10</p>
|
|
<p>UpgradeNote: The safe_asterisk script now checks that, if it was run by the
|
|
root user, the /etc/asterisk/startup.d directory and all the files it contains
|
|
are owned by root. If the checks fail, safe_asterisk will exit with an error
|
|
and Asterisk will not be started. Additionally, the default logging
|
|
destination is now stderr instead of tty "9" which probably won't exist
|
|
in modern systems.</p>
|
|
<p>Resolves: #GHSA-v9q8-9j8m-5xwp</p>
|
|
<h4>res_stir_shaken: Test for missing semicolon in Identity header.</h4>
|
|
<p>Author: George Joseph
|
|
Date: 2025-07-31</p>
|
|
<p>ast_stir_shaken_vs_verify() now makes sure there's a semicolon in
|
|
the Identity header to prevent a possible segfault.</p>
|
|
<p>Resolves: #GHSA-mrq5-74j5-f5cr</p>
|
|
</body></html>
|