|
|
| |
|
| |
asterisk: several vulnerabilities
| Package(s): | asterisk |
CVE #(s): | CVE-2005-3559
CVE-2006-1827
|
| Created: | May 1, 2006 |
Updated: | May 3, 2006 |
| Description: |
Several problems have been discovered in Asterisk, an open source
private branch exchange (telephone control center).
- Adam Pointon discovered that due to missing input sanitizing it is
possible to retrieve recorded phone messages for a different extension.
(CVE-2005-3559)
- Emmanouel Kellinis discovered an integer signedness error that could
trigger a buffer overflow and hence allow the execution of arbitrary code.
(CVE-2006-1827)
|
| Alerts: |
|
( Log in to post comments)
|
|
|