LWN.net Logo

Advertisement

Dedicated and managed servers in U.S and Europe. Famous 24x7 support and customizations from HCServers.net!

Advertise here

Package(s):asterisk CVE #(s):CVE-2007-6430 CVE-2008-1332 CVE-2008-1333
Created:March 20, 2008 Updated:April 25, 2008
Description: From the Debian alert:

CVE-2007-6430: Tilghman Lesher discovered that database-based registrations are insufficiently validated. This only affects setups, which are configured to run without a password and only host-based authentication.

CVE-2008-1332: Jason Parker discovered that insufficient validation of From: headers inside the SIP channel driver may lead to authentication bypass and the potential external initiation of calls.

Alerts:
Debian DSA-1525-1 2008-03-20
Fedora FEDORA-2008-2620 2008-03-21
Fedora FEDORA-2008-2554 2008-03-21
Gentoo 200804-13 2008-04-14
SuSE SUSE-SR:2008:010 2008-04-25

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.