LWN.net Logo

asterisk: code execution

Package(s):asterisk CVE #(s):CVE-2012-1183 CVE-2012-1184
Created:March 28, 2012 Updated:May 4, 2012
Description: The asterisk telephony system prior to version 1.8.10.1 suffers from a stack overrun in milliwatt_generate() and a buffer overflow vulnerability in ast_parse_digest(). Either could be exploited to execute arbitrary code.
Alerts:
Gentoo 201203-21 2012-03-28
Fedora FEDORA-2012-4318 2012-03-31
Fedora FEDORA-2012-4259 2012-03-31
Debian DSA-2460-1 2012-04-25
Fedora FEDORA-2012-6612 2012-05-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds