|
|
| |
|
| |
asterisk: denial of service
| Package(s): | asterisk |
CVE #(s): | CVE-2012-3553
|
| Created: | June 26, 2012 |
Updated: | June 27, 2012 |
| Description: |
From the Red Hat bugzilla:
AST-2012-008 previously dealt with a denial of service attack exploitable in the Skinny channel driver that occurred when certain messages are sent after a previously registered station sends an Off Hook message. Unresolved in that patch is an issue in the Asterisk 10 releases, wherein, if a Station Key Pad Button Message is processed after an Off Hook message, the channel driver will inappropriately dereference a Null pointer.
Similar to AST-2012-008, a remote attacker with a valid SCCP ID can can use this vulnerability by closing a connection to the Asterisk server when a station is in the "Off Hook" call state and crash the server.
This only affects version 10, and is fixed in 10.5.1. |
| Alerts: |
|
( Log in to post comments)
|
|
|