Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69568
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2225-1)
Summary:The remote host is missing an update for the Debian 'asterisk' package(s) announced via the DSA-2225-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'asterisk' package(s) announced via the DSA-2225-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in Asterisk, an Open Source PBX and telephony toolkit.

CVE-2011-1147

Matthew Nicholson discovered that incorrect handling of UDPTL packets may lead to denial of service or the execution of arbitrary code.

CVE-2011-1174

Blake Cornell discovered that incorrect connection handling in the manager interface may lead to denial of service.

CVE-2011-1175

Blake Cornell and Chris May discovered that incorrect TCP connection handling may lead to denial of service.

CVE-2011-1507

Tzafrir Cohen discovered that insufficient limitation of connection requests in several TCP based services may lead to denial of service. Please see AST-2011-005 for details.

CVE-2011-1599

Matthew Nicholson discovered a privilege escalation vulnerability in the manager interface.

For the oldstable distribution (lenny), this problem has been fixed in version 1:1.4.21.2~
dfsg-3+lenny2.1.

For the stable distribution (squeeze), this problem has been fixed in version 1:1.6.2.9-2+squeeze2.

For the unstable distribution (sid), this problem has been fixed in version 1:1.8.3.3-1.

We recommend that you upgrade your asterisk packages.

Affected Software/OS:
'asterisk' package(s) on Debian 5, Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1147
BugTraq ID: 46474
http://www.securityfocus.com/bid/46474
Debian Security Information: DSA-2225 (Google Search)
http://www.debian.org/security/2011/dsa-2225
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055030.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055421.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055634.html
http://www.openwall.com/lists/oss-security/2011/03/11/2
http://www.openwall.com/lists/oss-security/2011/03/11/8
http://www.securitytracker.com/id?1025101
http://secunia.com/advisories/43429
http://secunia.com/advisories/43702
http://www.vupen.com/english/advisories/2011/0635
Common Vulnerability Exposure (CVE) ID: CVE-2011-1174
1025223
http://securitytracker.com/id?1025223
46897
http://www.securityfocus.com/bid/46897
ADV-2011-0686
http://www.vupen.com/english/advisories/2011/0686
ADV-2011-0790
http://www.vupen.com/english/advisories/2011/0790
DSA-2225
FEDORA-2011-3942
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/057163.html
FEDORA-2011-3945
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/057156.html
FEDORA-2011-3958
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056945.html
[oss-security] 20110317 CVE request for Asterisk flaws
http://openwall.com/lists/oss-security/2011/03/17/5
[oss-security] 20110321 Re: CVE request for Asterisk flaws
http://openwall.com/lists/oss-security/2011/03/21/12
asterisk-writes-dos(66139)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66139
http://downloads.asterisk.org/pub/security/AST-2011-003.html
https://bugzilla.redhat.com/show_bug.cgi?id=688675
Common Vulnerability Exposure (CVE) ID: CVE-2011-1175
1025224
http://securitytracker.com/id?1025224
46898
http://www.securityfocus.com/bid/46898
asterisk-handletcptlsconnection-dos(66140)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66140
http://downloads.asterisk.org/pub/security/AST-2011-004.html
https://bugzilla.redhat.com/show_bug.cgi?id=688678
Common Vulnerability Exposure (CVE) ID: CVE-2011-1507
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058922.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059702.html
http://securitytracker.com/id?1025432
http://secunia.com/advisories/44197
http://secunia.com/advisories/44529
http://www.vupen.com/english/advisories/2011/1086
http://www.vupen.com/english/advisories/2011/1107
http://www.vupen.com/english/advisories/2011/1188
Common Vulnerability Exposure (CVE) ID: CVE-2011-1599
1025433
http://securitytracker.com/id?1025433
44197
44529
47537
http://www.securityfocus.com/bid/47537
ADV-2011-1086
ADV-2011-1107
ADV-2011-1188
FEDORA-2011-5835
FEDORA-2011-6208
[oss-security] 20110422 Re: CVE Request -- Asterisk Security Vulnerability
http://openwall.com/lists/oss-security/2011/04/22/6
http://downloads.digium.com/pub/security/AST-2011-006.html
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.