Asterisk 13.38.1, 16.15.1, 17.9.1 and 18.1.1 Now Available (Security)

The Asterisk Development Team would like to announce security releases for
Asterisk 13, 16, 17 and 18. The available releases are released as versions
13.38.1, 16.15.1, 17.9.1 and 18.1.1.

These releases are available for immediate download at

https://downloads.asterisk.org/pub/telephony/asterisk/releases

The following security vulnerabilities were resolved in these versions:

  • AST-2020-003: Remote crash in res_pjsip_diversion
    A crash can occur in Asterisk when a SIP message is received that has a
    History-Info header, which contains a tel-uri.

 

  • AST-2020-004: Remote crash in res_pjsip_diversion
    A crash can occur in Asterisk when a SIP 181 response is received that has a
    Diversion header, which contains a tel-uri.
For a full list of changes in the current releases, please see the ChangeLogs:

ChangeLog-13.38.1
ChangeLog-16.15.1
ChangeLog-17.9.1
ChangeLog-18.1.1

The security advisories are available at:

AST-2020-003.pdf
AST-2020-004.pdf

Thank you for your continued support of Asterisk!

What can we help you find?