From 5da1497b742194b535f13e155b87bd698772a4b6 Mon Sep 17 00:00:00 2001 From: Asterisk Development Team Date: Thu, 5 Feb 2026 16:50:46 +0000 Subject: [PATCH] Update for 22.8.2 --- .version | 2 +- CHANGES.html | 2 +- CHANGES.md | 2 +- ChangeLogs/ChangeLog-22.8.2.html | 103 ++++++++++++++++++++++++++ ChangeLogs/ChangeLog-22.8.2.md | 119 +++++++++++++++++++++++++++++++ README.html | 4 +- README.md | 2 +- 7 files changed, 228 insertions(+), 6 deletions(-) create mode 100644 ChangeLogs/ChangeLog-22.8.2.html create mode 100644 ChangeLogs/ChangeLog-22.8.2.md diff --git a/.version b/.version index baa600584f..955174f9da 100644 --- a/.version +++ b/.version @@ -1 +1 @@ -22.8.1 +22.8.2 diff --git a/CHANGES.html b/CHANGES.html index 03103a6b29..905be0926e 120000 --- a/CHANGES.html +++ b/CHANGES.html @@ -1 +1 @@ -ChangeLogs/ChangeLog-22.8.1.html \ No newline at end of file +ChangeLogs/ChangeLog-22.8.2.html \ No newline at end of file diff --git a/CHANGES.md b/CHANGES.md index 2fb43aef03..6c73404570 120000 --- a/CHANGES.md +++ b/CHANGES.md @@ -1 +1 @@ -ChangeLogs/ChangeLog-22.8.1.md \ No newline at end of file +ChangeLogs/ChangeLog-22.8.2.md \ No newline at end of file diff --git a/ChangeLogs/ChangeLog-22.8.2.html b/ChangeLogs/ChangeLog-22.8.2.html new file mode 100644 index 0000000000..7e16ef4d8a --- /dev/null +++ b/ChangeLogs/ChangeLog-22.8.2.html @@ -0,0 +1,103 @@ +ChangeLog for asterisk-22.8.2 +

Change Log for Release asterisk-22.8.2

+

Links:

+ +

Summary:

+ +

User Notes:

+ +

Upgrade Notes:

+ +

Developer Notes:

+

Commit Authors:

+ +

Issue and Commit Detail:

+

Closed Issues:

+ +

Commits By Author:

+ +

Commit List:

+ +

Commit Details:

+

xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile.

+

Author: George Joseph + Date: 2026-01-15

+

The xmlReadFile XML_PARSE_NOENT flag, which allows parsing of external + entities, could allow a potential XXE injection attack. Replacing it with + XML_PARSE_NONET, which prevents network access, is safer.

+

Resolves: #GHSA-85x7-54wr-vh42

+

ast_coredumper: check ast_debug_tools.conf permissions

+

Author: Mike Bradeen + Date: 2026-01-15

+

Prevent ast_coredumper from using ast_debug_tools.conf files that are + not owned by root or are writable by other users or groups.

+

Prevent ast_logescalator and ast_loggrabber from doing the same if + they are run as root.

+

Resolves: #GHSA-rvch-3jmx-3jf3

+

UserNote: ast_debug_tools.conf must be owned by root and not be + writable by other users or groups to be used by ast_coredumper or + by ast_logescalator or ast_loggrabber when run as root.

+

http.c: Change httpstatus to default disabled and sanitize output.

+

Author: George Joseph + Date: 2026-01-15

+

To address potential security issues, the httpstatus page is now disabled + by default and the echoed query string and cookie output is html-escaped.

+

Resolves: #GHSA-v6hp-wh3r-cwxh

+

UpgradeNote: To prevent possible security issues, the /httpstatus page + served by the internal web server is now disabled by default. To explicitly + enable it, set enable_status=yes in http.conf.

+

ast_coredumper: create gdbinit file with restrictive permissions

+

Author: Mike Bradeen + Date: 2026-01-15

+

Modify gdbinit to use the install command with explicit permissions (-m 600) + when creating the .ast_coredumper.gdbinit file. This ensures the file is + created with restricted permissions (readable/writable only by the owner) + to avoid potential privilege escalation.

+

Resolves: #GHSA-xpc6-x892-v83c

+ diff --git a/ChangeLogs/ChangeLog-22.8.2.md b/ChangeLogs/ChangeLog-22.8.2.md new file mode 100644 index 0000000000..793b692d16 --- /dev/null +++ b/ChangeLogs/ChangeLog-22.8.2.md @@ -0,0 +1,119 @@ + +## Change Log for Release asterisk-22.8.2 + +### Links: + + - [Full ChangeLog](https://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-22.8.2.html) + - [GitHub Diff](https://github.com/asterisk/asterisk/compare/22.8.1...22.8.2) + - [Tarball](https://downloads.asterisk.org/pub/telephony/asterisk/asterisk-22.8.2.tar.gz) + - [Downloads](https://downloads.asterisk.org/pub/telephony/asterisk) + +### Summary: + +- Commits: 4 +- Commit Authors: 2 +- Issues Resolved: 0 +- Security Advisories Resolved: 4 + - [GHSA-85x7-54wr-vh42](https://github.com/asterisk/asterisk/security/advisories/GHSA-85x7-54wr-vh42): Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection + - [GHSA-rvch-3jmx-3jf3](https://github.com/asterisk/asterisk/security/advisories/GHSA-rvch-3jmx-3jf3): ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation + - [GHSA-v6hp-wh3r-cwxh](https://github.com/asterisk/asterisk/security/advisories/GHSA-v6hp-wh3r-cwxh): The Asterisk embedded web server's /httpstatus page echos user supplied values(cookie and query string) without sanitization + - [GHSA-xpc6-x892-v83c](https://github.com/asterisk/asterisk/security/advisories/GHSA-xpc6-x892-v83c): ast_coredumper runs as root, and writes gdb init file to world writeable folder; leading to potential privilege escalation + +### User Notes: + +- #### ast_coredumper: check ast_debug_tools.conf permissions + ast_debug_tools.conf must be owned by root and not be + writable by other users or groups to be used by ast_coredumper or + by ast_logescalator or ast_loggrabber when run as root. + + +### Upgrade Notes: + +- #### http.c: Change httpstatus to default disabled and sanitize output. + To prevent possible security issues, the `/httpstatus` page + served by the internal web server is now disabled by default. To explicitly + enable it, set `enable_status=yes` in http.conf. + + +### Developer Notes: + + +### Commit Authors: + +- George Joseph: (2) +- Mike Bradeen: (2) + +## Issue and Commit Detail: + +### Closed Issues: + + - !GHSA-85x7-54wr-vh42: Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection + - !GHSA-rvch-3jmx-3jf3: ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation + - !GHSA-v6hp-wh3r-cwxh: The Asterisk embedded web server's /httpstatus page echos user supplied values(cookie and query string) without sanitization + - !GHSA-xpc6-x892-v83c: ast_coredumper runs as root, and writes gdb init file to world writeable folder; leading to potential privilege escalation + +### Commits By Author: + +- #### George Joseph (2): + +- #### Mike Bradeen (2): + +### Commit List: + +- xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile. +- ast_coredumper: check ast_debug_tools.conf permissions +- http.c: Change httpstatus to default disabled and sanitize output. +- ast_coredumper: create gdbinit file with restrictive permissions + +### Commit Details: + +#### xml.c: Replace XML_PARSE_NOENT with XML_PARSE_NONET for xmlReadFile. + Author: George Joseph + Date: 2026-01-15 + + The xmlReadFile XML_PARSE_NOENT flag, which allows parsing of external + entities, could allow a potential XXE injection attack. Replacing it with + XML_PARSE_NONET, which prevents network access, is safer. + + Resolves: #GHSA-85x7-54wr-vh42 + +#### ast_coredumper: check ast_debug_tools.conf permissions + Author: Mike Bradeen + Date: 2026-01-15 + + Prevent ast_coredumper from using ast_debug_tools.conf files that are + not owned by root or are writable by other users or groups. + + Prevent ast_logescalator and ast_loggrabber from doing the same if + they are run as root. + + Resolves: #GHSA-rvch-3jmx-3jf3 + + UserNote: ast_debug_tools.conf must be owned by root and not be + writable by other users or groups to be used by ast_coredumper or + by ast_logescalator or ast_loggrabber when run as root. + +#### http.c: Change httpstatus to default disabled and sanitize output. + Author: George Joseph + Date: 2026-01-15 + + To address potential security issues, the httpstatus page is now disabled + by default and the echoed query string and cookie output is html-escaped. + + Resolves: #GHSA-v6hp-wh3r-cwxh + + UpgradeNote: To prevent possible security issues, the `/httpstatus` page + served by the internal web server is now disabled by default. To explicitly + enable it, set `enable_status=yes` in http.conf. + +#### ast_coredumper: create gdbinit file with restrictive permissions + Author: Mike Bradeen + Date: 2026-01-15 + + Modify gdbinit to use the install command with explicit permissions (-m 600) + when creating the .ast_coredumper.gdbinit file. This ensures the file is + created with restricted permissions (readable/writable only by the owner) + to avoid potential privilege escalation. + + Resolves: #GHSA-xpc6-x892-v83c + diff --git a/README.html b/README.html index a33acc7380..438e828d1f 100644 --- a/README.html +++ b/README.html @@ -1,4 +1,4 @@ -Readme for asterisk-22.8.1 +Readme for asterisk-22.8.2

The Asterisk(R) Open Source PBX

By Mark Spencer <markster@digium.com> and the Asterisk.org developer community.
 Copyright (C) 2001-2025 Sangoma Technologies Corporation and other copyright holders.
@@ -37,7 +37,7 @@ hardware.

If you are updating from a previous version of Asterisk, make sure you read the Change Logs.

-

Change Logs

+

Change Logs

NEW INSTALLATIONS

diff --git a/README.md b/README.md index 881327f087..6be0a24f93 100644 --- a/README.md +++ b/README.md @@ -55,7 +55,7 @@ If you are updating from a previous version of Asterisk, make sure you read the Change Logs. -[Change Logs](ChangeLogs/ChangeLog-22.8.1.html) +[Change Logs](ChangeLogs/ChangeLog-22.8.2.html) ### NEW INSTALLATIONS