Security & Memory Hotfix Available for V18 Update 3

Status
Not open for further replies.
All of our instances are running fine following the hotfix, I couldn't determine any significant change in memory consumption, which could mean that we didn't hit the memory leak before.
We also did the upgrade to SBC 18.1.36 at the same time.

Could someone from 3CX comment which exact service was affected by potential memory leak ?

Here is a list of the processes relevant to 3CX we have running on the machines:

3CXAudioProvider
3cxSystemService
3CXManagementConsole
3CXGatewayService
CloudServicesWatcher
3CXSLDBServ
3CXMediaServer
3CXCallFlow
TcxQMsrv
3CXIVR
3CXPhoneSystem
postgres
 
Could someone from 3CX comment which exact service was affected by potential memory leak ?
It was the SIP server service (3CXPhoneSystem), but don't think it was something huge, we just noticed that it would creep up slightly over time.

Generally the hotfix addressed this well before any system could run long enough to cause any real problem.
 
Anyone else NOT getting prompted for "18.0 SP3? I am still on "18.0 (Build 314)". I am running this instance on a RaspberryPi 4B-8GB. I just updated a Linux install on a mini-PC, but this one is not yet seeing this update.
 
Anyone else NOT getting prompted for "18.0 SP3? I am still on "18.0 (Build 314)". I am running this instance on a RaspberryPi 4B-8GB. I just updated a Linux install on a mini-PC, but this one is not yet seeing this update.
Update 3 is not currently supporting the PBX on Raspberry Pi. See the announcement below. I'd recommend moving to cloud hosting and convert the Pi to an SBC. If that is not possible, or you just want to keep a local server, then use the 3CX ISO to build a new server on another computer or as a VM.

From https://www.3cx.com/blog/releases/v18-update-3-final/

Update 3 unavailable on Raspberry Pi PBX​

Raspberry is undergoing some changes which will bring future builds of its operating system in line with Debian. When 3CX supports Debian 11 (bullseye) we will look at supporting Raspberry once again. For the moment update 3 will not be available for Raspberry Pi.

3CX SBC will remain supported on Raspberry Pi devices. As a solution to stay on the latest update, move to Hosted by 3CX and use the Pi device as a 3CX SBC.
 
That seems about right... My infatuation with the RPi platform has waned since I started dabbling with it about 9 months ago. I am still an AMD/Intel person, and have an old HP Core i3 (Gen4) I can move over to for the time being. This is more of a home/hobby thing for me, so not personally going cloud for my use. Time to scrape up more $ for decent new HW while I am upgrading everything!
 
  • Like
Reactions: accentlogic
Last edited:
  • Like
Reactions: SweetAction
This was mentioned on the SANS Daily Network Security Podcast this morning. I listen every morning.
Here is a link to the article about how the exploit works.
https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88
That is true, and I'll point you right to the last paragraph of the article:

"This was fixed with 3CX Version 18, Hotfix 1, Build 18.0.3.461 March 2022 and at the time looks good to me."

So anyone that has a Windows installation of 3CX V18 should immediately upgrade to V18 U3 Hotfix 1 (build 461).
We have sent out mailers to all users that we have detected that are on a vulnerable version informing them of the need to upgrade.
 
That is true, and I'll point you right to the last paragraph of the article:

"This was fixed with 3CX Version 18, Hotfix 1, Build 18.0.3.461 March 2022 and at the time looks good to me."

So anyone that has a Windows installation of 3CX V18 should immediately upgrade to V18 U3 Hotfix 1 (build 461).
We have sent out mailers to all users that we have detected that are on a vulnerable version informing them of the need to upgrade.
My opinion, in the article 3CX comes across as a responsible and concerned vendor. They appear to have worked with the researcher on the issue and got it fixed.
Good job 3CX !!!
 
I have a few customers on win v16 latest. Is it vulnerable?
 
I have a few customers on win v16 latest. Is it vulnerable?
Yes, and you need to update them immediately. Like @NickD_3CX just said 2 posts up.
To be precise, V16 Windows installation do not have the vulnerability, it is only the earlier versions of V18.
V18 Update 3 Hotfix 1 fixes the vulnerability.

Despite this though you should upgrade to V18 asap
 
To be precise, V16 Windows installation do not have the vulnerability, it is only the earlier versions of V18.
V18 Update 3 Hotfix 1 fixes the vulnerability.

Despite this though you should upgrade to V18 asap
Thanks Nick, We'll upgrade everything this weekend. Glad to know we dont have to rush with v16.
 
  • Like
Reactions: NickD_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet