Asterisk Security Release 18.9-cert6 Now Available

The Asterisk Development Team would like to announce security release
Certified Asterisk 18.9-cert6.

The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/certified-18.9-cert6
and
https://downloads.asterisk.org/pub/telephony/certified-asterisk

The following security advisories were resolved in this release:

Change Log for Release asterisk-certified-18.9-cert6

Links:

Summary:

  • res_pjsip_header_funcs: Duplicate new header value, don’t copy.
  • res_rtp_asterisk.c: Check DTLS packets against ICE candidate list
  • manager.c: Prevent path traversal with GetConfig.
  • res_pjsip: disable raw bad packet logging

What can we help you find?