Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58577
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1358-1)
Summary:The remote host is missing an update for the Debian 'asterisk' package(s) announced via the DSA-1358-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'asterisk' package(s) announced via the DSA-1358-1 advisory.

Vulnerability Insight:
Several remote vulnerabilities have been discovered in Asterisk, a free software PBX and telephony toolkit. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-1306

Mu Security discovered that a NULL pointer dereference in the SIP implementation could lead to denial of service.

CVE-2007-1561

Inria Lorraine discovered that a programming error in the SIP implementation could lead to denial of service.

CVE-2007-2294

It was discovered that a NULL pointer dereference in the manager interface could lead to denial of service.

CVE-2007-2297

It was discovered that a programming error in the SIP implementation could lead to denial of service.

CVE-2007-2488

Tim Panton and Birgit Arkestein discovered that a programming error in the IAX2 implementation could lead to information disclosure.

CVE-2007-3762

Russell Bryant discovered that a buffer overflow in the IAX implementation could lead to the execution of arbitrary code.

CVE-2007-3763

Chris Clark and Zane Lackey discovered that several NULL pointer dereferences in the IAX2 implementation could lead to denial of service.

CVE-2007-3764

Will Drewry discovered that a programming error in the Skinny implementation could lead to denial of service.

For the oldstable distribution (sarge) these problems have been fixed in version 1.0.7.dfsg.1-2sarge5.

For the stable distribution (etch) these problems have been fixed in version 1:1.2.13~
dfsg-2etch1.

For the unstable distribution (sid) these problems have been fixed in version 1:1.4.11~
dfsg-1.

We recommend that you upgrade your Asterisk packages.

Affected Software/OS:
'asterisk' package(s) on Debian 3.1, Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-1306
BugTraq ID: 22838
http://www.securityfocus.com/bid/22838
CERT/CC vulnerability note: VU#228032
http://www.kb.cert.org/vuls/id/228032
Debian Security Information: DSA-1358 (Google Search)
http://www.debian.org/security/2007/dsa-1358
http://security.gentoo.org/glsa/glsa-200703-14.xml
http://labs.musecurity.com/advisories/MU-200703-01.txt
http://www.osvdb.org/33888
http://www.securitytracker.com/id?1017723
http://secunia.com/advisories/24380
http://secunia.com/advisories/24578
http://secunia.com/advisories/25582
SuSE Security Announcement: SUSE-SA:2007:034 (Google Search)
http://www.novell.com/linux/security/advisories/2007_34_asterisk.html
http://www.vupen.com/english/advisories/2007/0830
XForce ISS Database: asterisk-sip-channeldriver-dos(32830)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32830
Common Vulnerability Exposure (CVE) ID: CVE-2007-1561
BugTraq ID: 23031
http://www.securityfocus.com/bid/23031
Bugtraq: 20070321 Two new DoS Vulnerabilities in Asterisk Fixed (Google Search)
http://www.securityfocus.com/archive/1/463434/100/0/threaded
http://marc.info/?l=full-disclosure&m=117432783011737&w=2
http://security.gentoo.org/glsa/glsa-200704-01.xml
http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html
http://www.osvdb.org/34479
http://www.securitytracker.com/id?1017794
http://secunia.com/advisories/24564
http://secunia.com/advisories/24719
http://www.vupen.com/english/advisories/2007/1039
XForce ISS Database: asterisk-sip-invite-dos(33068)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33068
Common Vulnerability Exposure (CVE) ID: CVE-2007-2294
BugTraq ID: 23649
http://www.securityfocus.com/bid/23649
Bugtraq: 20070425 ASA-2007-012: Remote Crash Vulnerability in Manager Interface (Google Search)
http://www.securityfocus.com/archive/1/466911/100/0/threaded
http://www.osvdb.org/35369
http://www.securitytracker.com/id?1017955
http://secunia.com/advisories/24977
http://securityreason.com/securityalert/2646
http://www.vupen.com/english/advisories/2007/1534
XForce ISS Database: asterisk-interface-dos(33886)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33886
Common Vulnerability Exposure (CVE) ID: CVE-2007-2297
BugTraq ID: 24359
http://www.securityfocus.com/bid/24359
Bugtraq: 20070425 ASA-2007-011: Multiple problems in SIP channel parser handling response codes (Google Search)
http://www.securityfocus.com/archive/1/466882/100/0/threaded
http://bugs.digium.com/view.php?id=9313
http://www.securitytracker.com/id?1017954
http://securityreason.com/securityalert/2644
XForce ISS Database: asterisk-sip-response-dos(33892)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33892
Common Vulnerability Exposure (CVE) ID: CVE-2007-2488
BugTraq ID: 23824
http://www.securityfocus.com/bid/23824
http://osvdb.org/35769
http://secunia.com/advisories/25134
http://www.vupen.com/english/advisories/2007/1661
XForce ISS Database: asterisk-iax2-information-disclosure(34085)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34085
Common Vulnerability Exposure (CVE) ID: CVE-2007-3762
BugTraq ID: 24949
http://www.securityfocus.com/bid/24949
http://security.gentoo.org/glsa/glsa-200802-11.xml
http://www.securitytracker.com/id?1018407
http://secunia.com/advisories/26099
http://secunia.com/advisories/29051
SuSE Security Announcement: SUSE-SR:2007:015 (Google Search)
http://www.novell.com/linux/security/advisories/2007_15_sr.html
http://www.vupen.com/english/advisories/2007/2563
XForce ISS Database: asterisk-iax2channeldriver-bo(35466)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35466
Common Vulnerability Exposure (CVE) ID: CVE-2007-3763
BugTraq ID: 24950
http://www.securityfocus.com/bid/24950
Common Vulnerability Exposure (CVE) ID: CVE-2007-3764
XForce ISS Database: asterisk-skinny-driver-dos(35478)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35478
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.