LWN.net Logo

asterisk: multiple vulnerabilities

Package(s):asterisk CVE #(s):CVE-2008-3903 CVE-2009-3727 CVE-2007-2383
Created:December 15, 2009 Updated:June 4, 2010
Description: From the Debian advisory:

It is possible to determine a valid SIP username, when Digest authentication and authalwaysreject are enabled (AST-2009-003). (CVE-2008-3903)

It is possible to determine a valid SIP username via multiple crafted REGISTER messages (AST-2009-008). (CVE-2009-3727)

It was discovered that asterisk contains an obsolete copy of the Prototype JavaScript framework, which is vulnerable to several security issues. This copy is unused and now removed from asterisk (AST-2009-009). (CVE-2007-2383)

Alerts:
Gentoo 201006-20 2010-06-04
Debian DSA-1952-1 2009-12-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds