|
|
| |
|
| |
asterisk: multiple vulnerabilities
| Package(s): | asterisk |
CVE #(s): | CVE-2008-3903
CVE-2009-3727
CVE-2007-2383
|
| Created: | December 15, 2009 |
Updated: | June 4, 2010 |
| Description: |
From the Debian advisory:
It is possible to determine a valid SIP username, when Digest
authentication and authalwaysreject are enabled (AST-2009-003). (CVE-2008-3903)
It is possible to determine a valid SIP username via multiple crafted
REGISTER messages (AST-2009-008). (CVE-2009-3727)
It was discovered that asterisk contains an obsolete copy of the
Prototype JavaScript framework, which is vulnerable to several security
issues. This copy is unused and now removed from asterisk
(AST-2009-009). (CVE-2007-2383)
|
| Alerts: |
|
( Log in to post comments)
|
|
|