Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2013.0266
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2013-0266)
Summary:The remote host is missing an update for the 'asterisk' package(s) announced via the MGASA-2013-0266 advisory.
Description:Summary:
The remote host is missing an update for the 'asterisk' package(s) announced via the MGASA-2013-0266 advisory.

Vulnerability Insight:
A remotely exploitable crash vulnerability exists in the SIP channel
driver if an ACK with SDP is received after the channel has been
terminated. The handling code incorrectly assumes that the channel
will always be present (CVE-2013-5641).

A remotely exploitable crash vulnerability exists in the SIP channel
driver if an invalid SDP is sent in a SIP request that defines media
descriptions before connection information. The handling code
incorrectly attempts to reference the socket address information even
though that information has not yet been set (CVE-2013-5642).

Affected Software/OS:
'asterisk' package(s) on Mageia 3.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-5641
BugTraq ID: 62021
http://www.securityfocus.com/bid/62021
Bugtraq: 20130827 AST-2013-004: Remote Crash From Late Arriving SIP ACK With SDP (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2013-08/0175.html
http://seclists.org/bugtraq/2013/Aug/185
Debian Security Information: DSA-2749 (Google Search)
http://www.debian.org/security/2013/dsa-2749
http://www.mandriva.com/security/advisories?name=MDVSA-2013:223
http://osvdb.org/96691
http://www.securitytracker.com/id/1028956
http://secunia.com/advisories/54534
http://secunia.com/advisories/54617
Common Vulnerability Exposure (CVE) ID: CVE-2013-5642
BugTraq ID: 62022
http://www.securityfocus.com/bid/62022
Bugtraq: 20130827 AST-2013-005: Remote Crash when Invalid SDP is sent in SIP Request (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2013-08/0174.html
http://osvdb.org/96690
http://www.securitytracker.com/id/1028957
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.