./comms/asterisk21, The Asterisk Software PBX

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 21.12.3, Package name: asterisk-21.12.3, Maintainer: jnemeth

Asterisk is a complete PBX in software. It provides all of the
features you would expect from a PBX and more. Asterisk does voice
over IP in three protocols, and can interoperate with almost all
standards-based telephony equipment using relatively inexpensive
hardware.

Asterisk provides Voicemail services with Directory, Call Conferencing,
Interactive Voice Response, Call Queuing. It has support for
three-way calling, caller ID services, ADSI, SIP and IAX.

This is an standard version. It is secheduled to go to security
fixes only on November 18th, 2025, and EOL on November 18th, 2026.
See here for more information about Asterisk versions:
https://docs.asterisk.org/About-the-Project/Asterisk-Versions

Note that many things that have long been deprecated have now been
removed, such as chan_sip and app_macro. See here for a complete
list: http://docs.asterisk.org/Development/Asterisk-Module-Deprecations



Package options: asterisk-config, jabber, ldap, speex

Master sites: (Expand)


Version history: (Expand)


CVS history: (Expand)


   2026-07-13 06:13:31 by John Nemeth | Files touched by this commit (3)
Log message:
Update to Asterisk 21.12.3:

## Change Log for Release asterisk-21.12.3

### Links:

 - [Full \ 
ChangeLog](https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-21.12.3.html)
 - [GitHub Diff](https://github.com/asterisk/asterisk/compare/21.12.2...21.12.3)

### Summary:

- Commits: 21
- Commit Authors: 7
- Issues Resolved: 0
- Security Advisories Resolved: 20
  - \ 
[GHSA-3g56-cgrh-95p5](https://github.com/asterisk/asterisk/security/advisories/GHSA-3g56-cgrh-95p5): \ 
chan_unistim DIALPAGE digit handling can overflow phone_number and crash \ 
Asterisk
  - \ 
[GHSA-3rhj-hhw7-m6fw](https://github.com/asterisk/asterisk/security/advisories/GHSA-3rhj-hhw7-m6fw): \ 
NULL Pointer Dereference in HTTP AMI Digest Authentication
  - \ 
[GHSA-4pgv-j3mr-3rcp](https://github.com/asterisk/asterisk/security/advisories/GHSA-4pgv-j3mr-3rcp): \ 
Reflected XSS in Phone Provisioning HTTP Error Pages
  - \ 
[GHSA-589g-qgf8-m6mx](https://github.com/asterisk/asterisk/security/advisories/GHSA-589g-qgf8-m6mx): \ 
Stack buffer overflow in MWI NOTIFY Message-Account parsing
  - \ 
[GHSA-746q-794h-cc7f](https://github.com/asterisk/asterisk/security/advisories/GHSA-746q-794h-cc7f): \ 
Out-of-Bounds Read in Q.931 Information Element Parser (H.323 Addon)
  - \ 
[GHSA-8jhw-m2hg-vp3h](https://github.com/asterisk/asterisk/security/advisories/GHSA-8jhw-m2hg-vp3h): \ 
Heap Buffer Overflow in OGG/Speex File Playback (format_ogg_speex)
  - \ 
[GHSA-8jw3-ccr9-xrmf](https://github.com/asterisk/asterisk/security/advisories/GHSA-8jw3-ccr9-xrmf): \ 
Buffer over-read in Asterisk PJSIP MWI body parser
  - \ 
[GHSA-g8q2-p36q-94f6](https://github.com/asterisk/asterisk/security/advisories/GHSA-g8q2-p36q-94f6): \ 
Heap-use-after-free in Asterisk PJSIP TCP/SDP handling when TCP connection \ 
closes during SDP processing
  - \ 
[GHSA-h5hv-jmgj-92q2](https://github.com/asterisk/asterisk/security/advisories/GHSA-h5hv-jmgj-92q2): \ 
CVE-2022-37325 fix is absent from current chan_ooh323 Q.931 party-number parser
  - \ 
[GHSA-j2mm-57pq-jh94](https://github.com/asterisk/asterisk/security/advisories/GHSA-j2mm-57pq-jh94): \ 
Possible RED T.140 Generation Accumulation OOB Write
  - \ 
[GHSA-mxgm-8c6f-5p8f](https://github.com/asterisk/asterisk/security/advisories/GHSA-mxgm-8c6f-5p8f): \ 
Stack buffer overflow in res_xmpp XMPP namespace prefix handling
  - \ 
[GHSA-ph27-3m5q-mj5m](https://github.com/asterisk/asterisk/security/advisories/GHSA-ph27-3m5q-mj5m): \ 
SQL Injection in cel_pgsql and cel_tds via CELGenUserEvent eventtype Field
  - \ 
[GHSA-q9fr-m7g8-6ph5](https://github.com/asterisk/asterisk/security/advisories/GHSA-q9fr-m7g8-6ph5): \ 
Asterisk app_sms.c copies externally controlled SMS lengths into fixed in-struct \ 
buffers
  - \ 
[GHSA-qf8j-jp7h-c5hx](https://github.com/asterisk/asterisk/security/advisories/GHSA-qf8j-jp7h-c5hx): \ 
Out-of-Bounds Write in Codec2 Decoder Due to Floor/Ceil Sample Count Mismatch
  - \ 
[GHSA-r6c2-hwc2-j4mp](https://github.com/asterisk/asterisk/security/advisories/GHSA-r6c2-hwc2-j4mp): \ 
LDAP Filter Injection in res_config_ldap via SIP Username (Unauthenticated \ 
Information Disclosure)
  - \ 
[GHSA-vfhr-r9x9-c687](https://github.com/asterisk/asterisk/security/advisories/GHSA-vfhr-r9x9-c687): \ 
Possible RED T.140 Heap Buffer Overflow
  - \ 
[GHSA-vrfp-mg3q-3959](https://github.com/asterisk/asterisk/security/advisories/GHSA-vrfp-mg3q-3959): \ 
ARI setChannelVar bypasses live_dangerously and permits FILE() writes
  - \ 
[GHSA-wcvv-g26m-wx5c](https://github.com/asterisk/asterisk/security/advisories/GHSA-wcvv-g26m-wx5c): \ 
ARI REST-over-WebSocket read-only bypass allows arbitrary module path load and \ 
conditional RCE
  - \ 
[GHSA-x348-j6c9-77f3](https://github.com/asterisk/asterisk/security/advisories/GHSA-x348-j6c9-77f3): \ 
Stack Buffer Overflow in H.323 ooTrace() via Unbounded vsprintf into Fixed \ 
2048-byte Buffer
  - \ 
[GHSA-xgj6-2gc5-5x9c](https://github.com/asterisk/asterisk/security/advisories/GHSA-xgj6-2gc5-5x9c): \ 
ast_loggrabber executes python script in world writable directory(`/tmp`) \ 
leading to potential privilege escalation And RCE

### User Notes:

- #### acl: Add ACL support to http and ari
  A new section, type=restriction has been added to http.conf
  to allow an uri prefix based acl to be configured. See
  http.conf.sample for examples and more information.
  The user section of ari.conf can now contain an acl configuration
  to restrict users access. See ari.conf.sample for examples and more
  information

### Developer Notes:

- #### ARI: Make ARI applications respect live_dangerously.
  ARI applications can no longer call "dangerous" dialplan
  functions like DB(), FILE(), SHELL(), CURL(), STAT(), etc. without
  enabling "live_dangerously" in asterisk.conf.
  Resolves: #GHSA-vrfp-mg3q-3959

### Commit Authors:

- George Joseph: (6)
- Joshua C. Colp: (1)
- Mike Bradeen: (4)
- Milan Kyselica: (7)
- Pengpeng Hou: (1)
- Roberto Paleari: (1)
- ThatTotallyRealMyth: (1)

## Issue and Commit Detail:

### Closed Issues:

  - !GHSA-3g56-cgrh-95p5: chan_unistim DIALPAGE digit handling can overflow \ 
phone_number and crash Asterisk
  - !GHSA-3rhj-hhw7-m6fw: NULL Pointer Dereference in HTTP AMI Digest Authentication
  - !GHSA-4pgv-j3mr-3rcp: Reflected XSS in Phone Provisioning HTTP Error Pages
  - !GHSA-589g-qgf8-m6mx: Stack buffer overflow in MWI NOTIFY Message-Account parsing
  - !GHSA-746q-794h-cc7f: Out-of-Bounds Read in Q.931 Information Element Parser \ 
(H.323 Addon)
  - !GHSA-8jhw-m2hg-vp3h: Heap Buffer Overflow in OGG/Speex File Playback \ 
(format_ogg_speex)
  - !GHSA-8jw3-ccr9-xrmf: Buffer over-read in Asterisk PJSIP MWI body parser
  - !GHSA-g8q2-p36q-94f6: Heap-use-after-free in Asterisk PJSIP TCP/SDP handling \ 
when TCP connection closes during SDP processing
  - !GHSA-h5hv-jmgj-92q2: CVE-2022-37325 fix is absent from current chan_ooh323 \ 
Q.931 party-number parser
  - !GHSA-j2mm-57pq-jh94: Possible RED T.140 Generation Accumulation OOB Write
  - !GHSA-mxgm-8c6f-5p8f: Stack buffer overflow in res_xmpp XMPP namespace \ 
prefix handling
  - !GHSA-ph27-3m5q-mj5m: SQL Injection in cel_pgsql and cel_tds via \ 
CELGenUserEvent eventtype Field
  - !GHSA-q9fr-m7g8-6ph5: Asterisk app_sms.c copies externally controlled SMS \ 
lengths into fixed in-struct buffers
  - !GHSA-qf8j-jp7h-c5hx: Out-of-Bounds Write in Codec2 Decoder Due to \ 
Floor/Ceil Sample Count Mismatch
  - !GHSA-r6c2-hwc2-j4mp: LDAP Filter Injection in res_config_ldap via SIP \ 
Username (Unauthenticated Information Disclosure)
  - !GHSA-vfhr-r9x9-c687: Possible RED T.140 Heap Buffer Overflow
  - !GHSA-vrfp-mg3q-3959: ARI setChannelVar bypasses live_dangerously and \ 
permits FILE() writes
  - !GHSA-wcvv-g26m-wx5c: ARI REST-over-WebSocket read-only bypass allows \ 
arbitrary module path load and conditional RCE
  - !GHSA-x348-j6c9-77f3: Stack Buffer Overflow in H.323 ooTrace() via Unbounded \ 
vsprintf into Fixed 2048-byte Buffer
  - !GHSA-xgj6-2gc5-5x9c: ast_loggrabber executes python script in world \ 
writable directory(`/tmp`) leading to potential privilege escalation And RCE

### Commit List:

-  ast_loggrabber: Install the ast_tsconvert.py script to a secure temp directory.
-  chan_unistim.c: Prevent overrun of phone_number field.
-  ooh323c: not checking for IE minimum length
-  res_ari: Ensure read-only users are properly authorized via REST Over WebSocket.
-  pjsip_message_filter: Use pj_strdup instead of pj_strassign to save local address.
-  ooh323c/ooq931.c: Ensure ooQ931Decode doesn't run out-of-bounds.
-  ARI: Make ARI applications respect live_dangerously.
-  res_rtp_asterisk.c: Address 2 potential T.140 RED buffer overruns.
-  res/res_pjsip_pubsub.c: Fix buffer over-read in MWI body parser
-  manager: Use remote address in user error logging
-  ooh323: Prevent potential buffer overflow in trace logging
-  app_sms: Bound protocol 1 SMS unpacking to fixed-size buffers
-  res_xmpp: Fix stack buffer overflow in namespace prefix handling
-  res_pjsip_pubsub: Add width limit to sscanf in MWI NOTIFY parser
-  res_config_ldap: Escape LDAP filter values per RFC 4515
-  cel_pgsql, cel_tds: Escape eventtype field to prevent SQL injection
-  http: Escape error page text to prevent reflected XSS
-  codec_codec2: Only process complete Codec2 frames in decoder
-  format_ogg_speex: Add bounds check to prevent heap buffer overflow
-  acl: Add ACL support to http and ari
-  build: Fix GCC discarded-qualifiers const errors.
   2026-05-14 18:42:34 by Ryo ONODERA | Files touched by this commit (1335)
Log message:
*: Recursive revbump from security/nettle-4.0
   2026-04-10 10:41:36 by Thomas Klausner | Files touched by this commit (12)
Log message:
*: remove OWNER definition

OWNER, when it was introduced, was to protect packages deep in the
infrastructure by emphasizing that they should not be touched by
non-MAINTAINERs.

No infrastructure package still sets OWNER.

Note: non-trivial change to packages should be passed by MAINTAINERs.

As discussed on tech-pkg.
   2026-03-30 04:38:39 by John Nemeth | Files touched by this commit (3) | Package updated
Log message:
Update to Asterisk 21.12.2:

Security update for PJSIP vulnerabilities.

## Change Log for Release asterisk-21.12.2

### Links:

 - [Full \ 
ChangeLog](https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-21.12.2.html)
 - [GitHub Diff](https://github.com/asterisk/asterisk/compare/21.12.1...21.12.2)

### Summary:

- Commits: 1
- Commit Authors: 1
- Issues Resolved: 1
- Security Advisories Resolved: 0

## Issue and Commit Detail:

### Closed Issues:

  - 1833: [bug]: Address security vulnerabilities in pjproject

### Commit List:

-  res_pjsip: Address pjproject security vulnerabilities

### Commit Details:

#### res_pjsip: Address pjproject security vulnerabilities
  Author: Mike Bradeen
  Date:   2026-03-25

  Address the following pjproject security vulnerabilities

  [GHSA-j29p-pvh2-pvqp - Buffer overflow in ICE with long \ 
username](https://github.com/pjsip/pjproject/security/advisories/GHSA-j29p-pvh2-pvqp)
  [GHSA-8fj4-fv9f-hjpc - Heap use-after-free in PJSIP presense subscription \ 
termination \ 
header](https://github.com/pjsip/pjproject/security/advisories/GHSA-8fj4-fv9f-hjpc)
  [GHSA-g88q-c2hm-q7p7 - ICE session use-after-free race \ 
conditions](https://github.com/pjsip/pjproject/security/advisories/GHSA-g88q-c2hm-q7p7)
  [GHSA-x5pq-qrp4-fmrj - Out-of-bounds read in SIP multipart \ 
parsing](https://github.com/pjsip/pjproject/security/advisories/GHSA-x5pq-qrp4-fmrj)

  Resolves: #1833
   2026-02-16 03:49:34 by John Nemeth | Files touched by this commit (3) | Package updated
Log message:
update to Asterisk 21.12.1:  this is a security fix

## Change Log for Release asterisk-21.12.1

### Links:

 - [Full \ 
ChangeLog](https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-21.12.1.html)
 - [GitHub Diff](https://github.com/asterisk/asterisk/compare/21.12.0...21.12.1)

### Summary:

- Commits: 4
- Commit Authors: 2
- Issues Resolved: 0
- Security Advisories Resolved: 4
  - \ 
[GHSA-85x7-54wr-vh42](https://github.com/asterisk/asterisk/security/advisories/GHSA-85x7-54wr-vh42): \ 
Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
  - \ 
[GHSA-rvch-3jmx-3jf3](https://github.com/asterisk/asterisk/security/advisories/GHSA-rvch-3jmx-3jf3): \ 
ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; \ 
potentially leading to privilege escalation
  - \ 
[GHSA-v6hp-wh3r-cwxh](https://github.com/asterisk/asterisk/security/advisories/GHSA-v6hp-wh3r-cwxh): \ 
The Asterisk embedded web server's /httpstatus page echos user supplied \ 
values(cookie and query string) without sanitization
  - \ 
[GHSA-xpc6-x892-v83c](https://github.com/asterisk/asterisk/security/advisories/GHSA-xpc6-x892-v83c): \ 
ast_coredumper runs as root, and writes gdb init file to world writeable folder; \ 
leading to potential privilege escalation

### User Notes:

- #### ast_coredumper: check ast_debug_tools.conf permissions
  ast_debug_tools.conf must be owned by root and not be
  writable by other users or groups to be used by ast_coredumper or
  by ast_logescalator or ast_loggrabber when run as root.

### Upgrade Notes:

- #### http.c: Change httpstatus to default disabled and sanitize output.
  To prevent possible security issues, the `/httpstatus` page
  served by the internal web server is now disabled by default.  To explicitly
  enable it, set `enable_status=yes` in http.conf.

## Issue and Commit Detail:

### Closed Issues:

  - !GHSA-85x7-54wr-vh42: Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to \ 
potential XXE Injection
  - !GHSA-rvch-3jmx-3jf3: ast_coredumper running as root sources \ 
ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege \ 
escalation
  - !GHSA-v6hp-wh3r-cwxh: The Asterisk embedded web server's /httpstatus page \ 
echos user supplied values(cookie and query string) without sanitization
  - !GHSA-xpc6-x892-v83c: ast_coredumper runs as root, and writes gdb init file \ 
to world writeable folder; leading to potential privilege escalation

### Commits By Author:

- #### George Joseph (2):

- #### Mike Bradeen (2):

### Commit List:

-  xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile.
-  ast_coredumper: check ast_debug_tools.conf permissions
-  http.c: Change httpstatus to default disabled and sanitize output.
-  ast_coredumper: create gdbinit file with restrictive permissions
   2026-02-06 11:06:21 by Thomas Klausner | Files touched by this commit (1305)
Log message:
*: recursive bump for nettle 4.0 shlib major bump
   2026-01-07 09:49:50 by Thomas Klausner | Files touched by this commit (2525)
Log message:
*: recursive bump for icu 78.1
   2025-12-01 04:42:23 by John Nemeth | Files touched by this commit (3) | Package updated
Log message:
Update to Asterisk 21.12.0.

## Change Log for Release asterisk-21.12.0

### Links:

 - [Full \ 
ChangeLog](https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-21.12.0.html)
 - [GitHub Diff](https://github.com/asterisk/asterisk/compare/21.11.0...21.12.0)

### Summary:

- Commits: 20
- Commit Authors: 10
- Issues Resolved: 13
- Security Advisories Resolved: 0

### User Notes:

- #### func_hangupcause.c: Add access to Reason headers via HANGUPCAUSE()
  Added a new option to HANGUPCAUSE to access additional
  information about hangup reason. Reason headers from pjsip
  could be read using 'tech_extended' cause type.

- #### chan_dahdi: Add DAHDI_CHANNEL function.
  The DAHDI_CHANNEL function allows for getting/setting
  certain properties about DAHDI channels from the dialplan.

### Upgrade Notes:

- #### res_audiosocket: add message types for all slin sample rates
  New audiosocket message types 0x11 - 0x18 has been added
  for slin12, slin16, slin24, slin32, slin44, slin48, slin96, and
  slin192 audio. External applications using audiosocket may need to be
  updated to support these message types if the audiosocket channel is
  created with one of these audio formats.

## Issue and Commit Detail:

### Closed Issues:

  - 1340: [bug]: comfort noise packet corrupted
  - 1419: [bug]: static code analysis issues in app_adsiprog.c
  - 1422: [bug]: static code analysis issues in apps/app_externalivr.c
  - 1425: [bug]: static code analysis issues in apps/app_queue.c
  - 1434: [improvement]: pbx_variables: Create real channel for dialplan eval \ 
CLI command
  - 1436: [improvement]: res_cliexec: Avoid unnecessary cast to char*
  - 1455: [new-feature]: chan_dahdi: Add DAHDI_CHANNEL function
  - 1467: [bug]: Crash in res_pjsip_refer during REFER progress teardown with \ 
PJSIP_TRANSFER_HANDLING(ari-only)
  - 1491: [bug]: Segfault: `channelstorage_cpp` fast lookup without lock \ 
(`get_by_name_exact`/`get_by_uniqueid`) leads to UAF during hangup
  - 1525: [bug]: chan_websocket: fix use of raw payload variable for string \ 
comparison in process_text_message
  - 1539: [bug]: safe_asterisk without TTY doesn't log to file
  - 1554: [bug]: safe_asterisk recurses into subdirectories of startup.d after f97361
  - 1578: [bug]: Deadlock with externalMedia custom channel id and cpp map \ 
channel backend