asterisk-addon

February 21

Asterisk 1.6.0 Beta 4 Released

Posted by jj
Filed under Asterisk, News | No Comments

It seems The Asterisk Development team has been working overtime to really crank out the code. Great work guys!

The Asterisk.org development team has released version 1.6.0 Beta 4.

This release contains the following improvements:

12020, a CLI formatting improvement
11964, added the ability to get the original called number on SS7 calls
11873, Added core API […]

October 16

AST-2007-023 - SQL Injection Vulnerability: cdr_addon_mysql

Posted by jj
Filed under Asterisk, News | No Comments

SQL Injection Vulnerability in cdr_addon_mysql was discovered and corrected by the release of Asterisk-addons 1.4.4 and Asterisk-addons 1.2.8.
From the announcement:
The source and destination numbers for a given call are not correctly escaped by the cdr_addon_mysql module when inserting a record. Therefore, a carefully crafted destination number sent to an Asterisk system running cdr_addon_mysql could escape […]