DSA-2460-1 asterisk -- several vulnerabilities

Related Vulnerabilities: CVE-2012-1183   CVE-2012-2414   CVE-2012-2415  

Several vulnerabilities were discovered in the Asterisk PBX and telephony toolkit: CVE-2012-1183 Russell Bryant discovered a buffer overflow in the Milliwatt application. CVE-2012-2414 David Woolley discovered a privilege escalation in the Asterisk manager interface. CVE-2012-2415 Russell Bryant discovered a buffer overflow in the Skinny driver. For the stable distribution (squeeze), this problem has been fixed in version 1:1.6.2.9-2+squeeze5. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your asterisk packages.

Debian Security Advisory

DSA-2460-1 asterisk -- several vulnerabilities

Date Reported:
25 Apr 2012
Affected Packages:
asterisk
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-1183, CVE-2012-2414, CVE-2012-2415.
More information:

Several vulnerabilities were discovered in the Asterisk PBX and telephony toolkit:

  • CVE-2012-1183

    Russell Bryant discovered a buffer overflow in the Milliwatt application.

  • CVE-2012-2414

    David Woolley discovered a privilege escalation in the Asterisk manager interface.

  • CVE-2012-2415

    Russell Bryant discovered a buffer overflow in the Skinny driver.

For the stable distribution (squeeze), this problem has been fixed in version 1:1.6.2.9-2+squeeze5.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your asterisk packages.