LWN.net Logo

asterisk: denial of service

Package(s):asterisk CVE #(s):CVE-2012-5976 CVE-2012-5977
Created:January 14, 2013 Updated:January 30, 2013
Description: From the CVE entries:

Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones allow remote attackers to cause a denial of service (daemon crash) via TCP data using the (1) SIP, (2) HTTP, or (3) XMPP protocol. (CVE-2012-5976)

Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache. (CVE-2012-5977)

Alerts:
Debian DSA-2605-1 2013-01-13
Debian DSA-2605-2 2013-01-19
Fedora FEDORA-2013-1003 2013-01-30
Fedora FEDORA-2013-0994 2013-01-30
Fedora FEDORA-2013-0992 2013-01-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds