Reply
 
Thread Tools Display Modes
  #1  
Old 04-20-10, 07:30 PM
wardmundy wardmundy is offline
Nerd Uno
 
Join Date: Oct 2007
Posts: 3,881
FreePBX Security Vulnerability
There is a very serious security vulnerability that needs to be patched by loading the very latest version of FreePBX Framework as soon as it becomes available for your version of FreePBX. Just displaying a CDR report in the FreePBX browser could compromise your system.

The 2.5 and 2.6 patches already have been released and probably 2.7 as well. Load this patch IMMEDIATELY!!!

Setup, Module Admin, Check for Updates on Line, Upgrade All

2.5.2.3: #4223 Security Vulnerability
2.6.0.2: #3805, #3707, #4188, #4223 Security Vulnerability

Last edited by wardmundy : 04-21-10 at 09:06 AM.
Reply With Quote
  #2  
Old 04-20-10, 07:54 PM
tm1000 tm1000 is offline
Guru
 
Join Date: Dec 2009
Location: Rancho Cucamonga, CA
Posts: 316
Thanks!!
__________________
Programmer: FreePBX (Endpoint Manager), 2600hz (Provisioner), Bluebox (Provisioner),
Reply With Quote
  #3  
Old 04-20-10, 09:44 PM
jtjacobs jtjacobs is offline
Junior Member
 
Join Date: Feb 2009
Posts: 8
Thanks for the Alert
Reply With Quote
  #4  
Old 04-20-10, 09:54 PM
jehowe jehowe is offline
Guru
 
Join Date: Nov 2007
Location: Lincolnshire, IL
Posts: 258
Thanks for the heads up Ward, the 2.7 (2.7.0.2) framework update was available.

It must be really bad, trivial, or both. The FreePBX note for this bug is- "details not provided to minimize exposure"
__________________
http://www.jeffhowe.net
Reply With Quote
  #5  
Old 04-20-10, 09:56 PM
mruge mruge is offline
Member
 
Join Date: Jan 2008
Location: Spokane, WA
Posts: 99
Done and Done! Thanks Ward!
__________________
Michael Ruge
Inland I.T. Solutions, LLC - Spokane, WA
Reply With Quote
  #6  
Old 04-20-10, 11:49 PM
jtjacobs jtjacobs is offline
Junior Member
 
Join Date: Feb 2009
Posts: 8
So, after I applied the patch, FreePBX started complaining about a default SQL password and a default Asterisk Manager Password. Should I just run passwd-master again?
Reply With Quote
  #7  
Old 04-21-10, 12:26 AM
jroper jroper is offline
Guru
 
Join Date: Oct 2007
Posts: 3,333
Hi

That's normal behaviour, and not an issue - they are only listening to localhost, so if some one gets that far, the AMI, and the database are the least of your worries.

Leave it all as it is.

Joe
__________________
www.star2billing.com
Commercial Open Source Telephony
Reply With Quote
  #8  
Old 04-21-10, 06:07 AM
wardmundy wardmundy is offline
Nerd Uno
 
Join Date: Oct 2007
Posts: 3,881
Originally Posted by jtjacobs View Post
So, after I applied the patch, FreePBX started complaining about a default SQL password and a default Asterisk Manager Password. Should I just run passwd-master again?
This thread will show you how to remove the warning messages.
Reply With Quote
  #9  
Old 04-21-10, 08:26 AM
wardmundy wardmundy is offline
Nerd Uno
 
Join Date: Oct 2007
Posts: 3,881
Just released an updated Incredible PBX that incorporates the security fix.
Reply With Quote
  #10  
Old 04-21-10, 10:30 AM
dswartz dswartz is offline
Guru
 
Join Date: Feb 2009
Posts: 575
I'd love to know what the bug was - I have never been a fan of security through obscurity
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 08:59 PM.


Design by Vjacheslav Trushkin, color scheme by ColorizeIt!.
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2007-2008, Ward Mundy & Associates