LWN.net Logo

asterisk: multiple vulnerabilities

Package(s):asterisk CVE #(s):CVE-2011-2529 CVE-2011-2535
Created:July 11, 2011 Updated:July 13, 2011
Description: From the Debian advisory:

Paul Belanger reported a vulnerability in Asterisk identified as AST-2011-008 (CVE-2011-2529) through which an unauthenticated attacker may crash an Asterisk server remotely. A package containing a null char causes the SIP header parser to alter unrelated memory structures.

Jared Mauch reported a vulnerability in Asterisk identified as AST-2011-009 through which an unauthenticated attacker may crash an Asterisk server remotely. If a user sends a package with a Contact header with a missing left angle bracket (<) the server will crash. A possible workaround is to disable chan_sip.

The vulnerability identified as AST-2011-010 (CVE-2011-2535) reported about an input validation error in the IAX2 channel driver. An unauthenticated attacker may crash an Asterisk server remotely by sending a crafted option control frame.

Alerts:
Gentoo 201110-21 2011-10-24
Fedora FEDORA-2011-8983 2011-07-02
Fedora FEDORA-2011-8914 2011-06-30
Debian DSA-2276-2 2011-07-11
Debian DSA-2276-1 2011-07-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds