[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2225-1 asterisk -- several issues

ID: oval:org.secpod.oval:def:600240Date: (C)2011-04-27   (M)2022-10-10
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in Asterisk, an Open Source PBX and telephony toolkit. CVE-2011-1147 Matthew Nicholson discovered that incorrect handling of UDPTL packets may lead to denial of service of the execution of arbitrary code. CVE-2011-1174 Blake Cornell discovered that incorrect connection handling in the manager interface may lead to denial of service. CVE-2011-1175 Blake Cornell and Chris May discovered that incorrect TCP connection handling may lead to denial of service. CVE-2011-1507 Tzafrir Cohen discovered that insufficient limitation of connection requests in several TCP based services may lead to denial of service. CVE-2011-1599 Matthew Nicholson discovered a privilege escalation vulnerability in the manager interface.

Platform:
Debian 5.0
Debian 6.0
Product:
asterisk
Reference:
DSA-2225-1
CVE-2011-1147
CVE-2011-1174
CVE-2011-1175
CVE-2011-1507
CVE-2011-1599
CVE    5
CVE-2011-1599
CVE-2011-1507
CVE-2011-1175
CVE-2011-1174
...
CPE    3
cpe:/a:asterisk:asterisk
cpe:/o:debian:debian_linux:5.x
cpe:/o:debian:debian_linux:6.x
XCCDF    1
xccdf_com.secpod_benchmark_sample-definitions

© SecPod Technologies