LWN.net Logo

asterisk: several vulnerabilities

Package(s):asterisk CVE #(s):CVE-2005-3559 CVE-2006-1827
Created:May 1, 2006 Updated:May 3, 2006
Description: Several problems have been discovered in Asterisk, an open source private branch exchange (telephone control center).
  • Adam Pointon discovered that due to missing input sanitizing it is possible to retrieve recorded phone messages for a different extension. (CVE-2005-3559)
  • Emmanouel Kellinis discovered an integer signedness error that could trigger a buffer overflow and hence allow the execution of arbitrary code. (CVE-2006-1827)
Alerts:
Debian DSA-1048-1 2006-05-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds