|
|
| |
| Asterisk is prone to a remote denial-of-service vulnerability. |
| |
Credit:
The information has been provided by Christoph Hebeisen.
The original article can be found at: http://www.securityfocus.com/bid/53723
|
| |
Vulnerable Systems:
* Asterisk Certified Asterisk 1.8.11-cert1
* Asterisk Asterisk 10.0.1
* Asterisk Asterisk 10.0
* Asterisk Asterisk 1.8.8 2
* Asterisk Asterisk 1.8.4 2
* Asterisk Asterisk 1.8.4 1
* Asterisk Asterisk 1.8.2 4
* Asterisk Asterisk 1.8.1
* Asterisk Asterisk 1.8
* Asterisk Asterisk 10.3.1
* Asterisk Asterisk 10.3.0
* Asterisk Asterisk 10.2.1
* Asterisk Asterisk 10.2.0
* Asterisk Asterisk 1.8.7.2
* Asterisk Asterisk 1.8.7.1
* Asterisk Asterisk 1.8.4.4
* Asterisk Asterisk 1.8.4.3
* Asterisk Asterisk 1.8.3.3
* Asterisk Asterisk 1.8.3.1
* Asterisk Asterisk 1.8.2.1
* Asterisk Asterisk 1.8.11.1
* Asterisk Asterisk 1.8.11.0
* Asterisk Asterisk 1.8.10.1
* Asterisk Asterisk 1.8.10.0
* Asterisk Asterisk 1.8.1.2
Immune Systems:
* Asterisk Certified Asterisk 1.8.11-cert2
* Asterisk Asterisk 10.4.1
* Asterisk Asterisk 1.8.12.1
Attackers can exploit this issue to trigger a NULL-pointer dereference and cause a system crash, denying service to legitimate users.
Vendor Status:
Vendor had issued an update for this vulnerability
Patch Availability:
http://downloads.asterisk.org/pub/security/AST-2012-008.pdf
CVE Information:
CVE-2012-2948
Disclosure Timeline:
Initial Release: May 29 2012
|
|
blog comments powered by
|