Re: Security Through Obscurity (was: Re: [asterisk-dev] asterisk 1.4.1/1.2.16 release question)

2007-03-05 Thread CA DM
try. I'm disappointed to see Digium acting as if it weren't. On Sun, 2007-03-04 at 12:00 -0700, [EMAIL PROTECTED] wrote: > Date: Sun, 04 Mar 2007 11:46:01 -0600 > From: "Kevin P. Fleming" <[EMAIL PROTECTED]> > Subject: Re: [asterisk-dev] asterisk 1.4.1/1.2.16

Security Through Obscurity (was: Re: [asterisk-dev] asterisk 1.4.1/1.2.16 release question)

2007-03-04 Thread Matthew Rubenstein
ppointed to see Digium acting as if it weren't. On Sun, 2007-03-04 at 12:00 -0700, [EMAIL PROTECTED] wrote: > Date: Sun, 04 Mar 2007 11:46:01 -0600 > From: "Kevin P. Fleming" <[EMAIL PROTECTED]> > Subject: Re: [asterisk-dev] asterisk 1.4.1/1.2.16 release quest

Re: [asterisk-dev] asterisk 1.4.1/1.2.16 release question

2007-03-04 Thread Kevin P. Fleming
Anthony Lamantia wrote: > "obvious reasons" .. ?, I really would like to know what the risk to my > asterisk servers are. We have never, and will never, help potential exploiters directly. The issue is that a very simple SIP packet can cause Asterisk to crash. Figuring out how to construct that

Re: [asterisk-dev] asterisk 1.4.1/1.2.16 release question

2007-03-04 Thread Anthony Lamantia
"obvious reasons" .. ?, I really would like to know what the risk to my asterisk servers are. On 3/4/07, Russell Bryant <[EMAIL PROTECTED]> wrote: Anthony Lamantia wrote: > where can i find more information regarding it (protocol, is it a > problem before authentication is required..etc) Det

Re: [asterisk-dev] asterisk 1.4.1/1.2.16 release question

2007-03-04 Thread Russell Bryant
Anthony Lamantia wrote: where can i find more information regarding it (protocol, is it a problem before authentication is required..etc) Details of how to exploit the problem are intentionally hard to find, for obvious reasons. -- Russell Bryant Software Engineer Digium, Inc. begin:vcard fn