LWN.net Logo

asterisk: multiple vulnerabilities

Package(s):asterisk CVE #(s):CVE-2011-4597 CVE-2011-4598
Created:December 19, 2011 Updated:December 21, 2011
Description: From the Debian advisory:

CVE-2011-4597: Ben Williams discovered that it was possible to enumerate SIP user names in some configurations.

CVE-2011-4598: Kristijan Vrban discovered that Asterisk can be crashed with malformed SIP packets if the "automon" feature is enabled.

Alerts:
Debian DSA-2367-1 2011-12-19
Fedora FEDORA-2012-4259 2012-03-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds