Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2232

Опубликовано: 22 фев. 2016
Источник: debian

Описание

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a zero length error correcting redundancy packet for a UDPTL FAX packet that is lost.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
asteriskfixed1:13.7.2~dfsg-1package
asteriskno-dsawheezypackage
asteriskend-of-lifesqueezepackage

Примечания

  • http://downloads.asterisk.org/pub/security/AST-2016-003.html

  • https://issues.asterisk.org/jira/browse/ASTERISK-25603

  • issue was introduced in 2006 with commit 0f5e4e47, so squeeze and previous also vulnerable

  • patch for 11 / jessie: https://code.asterisk.org/code/changelog/asterisk?cs=da2573a3779425654543d6ac4c4dd6871ce16720

  • all versions vulnerable, backport required for wheezy

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 10 лет назад

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a zero length error correcting redundancy packet for a UDPTL FAX packet that is lost.

CVSS3: 6.5
nvd
почти 10 лет назад

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a zero length error correcting redundancy packet for a UDPTL FAX packet that is lost.

CVSS3: 6.5
github
больше 3 лет назад

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a zero length error correcting redundancy packet for a UDPTL FAX packet that is lost.

fstec
почти 10 лет назад

Уязвимость систем управления IP-телефонией Asterisk и Certified Asterisk, позволяющая нарушителю вызвать отказ в обслуживании