WARNING! trixbox/FreePBX Security Alert!!! Immediate action required!

mickecarls
Posts: 98
Member Since:
2006-10-19

A very serious security vulnerability has been discovered by Kevin Lynn at GWU. It was demonstrated during the Atlanta Asterisk Users Conference this past weekend. It affects ALL FreePBX-based systems and could compromise not only your server but also your credentials on your server. All that is required to trigger the Trojan attack is displaying the CDR Report module within a browser.

This means that ALL trixbox versions are affected. We at FreePBX take this very seriously and released a fix as soon as the vulnerability was discovered.

However, since newer trixbox use a "forked" version of FreePBX there is no fix released by Fonality or andrew. Users using the old versions of trixbox should just check for updates and install the new Framework to be safe.

I urge Fonality and andrew to take action immediately and "fork" the new released FreePBX Framework so that you, trixbox customers, can continue to use trixbox and still be safe from attacks.
This just proves that "forking" FreePBX was a bad decision by Fonality.

Mikael Carlsson
FreePBX Development Team



Astrosmurfer
Posts: 643
Member Since:
2009-12-28
EEK! Here's hoping Fonality

EEK!

Here's hoping Fonality issues some kind of statement on this. This security flaw was demonstrated over a week ago and this is the first I am hearing of it.



mickecarls
Posts: 98
Member Since:
2006-10-19
Well well, no comment here

Well well, no comment here from Fonality or andrew, but they must have read it as there is an updated framework in the repository http://update.trixbox.org/modules/release/2.5/framework-2.5.2.3.t...

andrew, don't forget the 2.4 version, that version is also affected.



andrew
Posts: 1472
Member Since:
2006-05-30
Thanks for the update. We

Thanks for the update. We posted a fix. Here is the info on how to install it.

http://trixbox.org/devblog/security-bug-found-pbxconfig



Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.