| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.69591 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: asterisk14 |
| Summary: | FreeBSD Ports: asterisk14 |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following packages are affected: asterisk14 asterisk16 asterisk18 CVE-2011-1507 Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections. Solution: Update your system with the appropriate patches or software upgrades. http://downloads.asterisk.org/pub/security/AST-2011-005.pdf http://downloads.asterisk.org/pub/security/AST-2011-006.pdf http://www.vuxml.org/freebsd/3c7d565a-6c64-11e0-813a-6c626dd55a41.html |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-1507 Debian Security Information: DSA-2225 (Google Search) http://www.debian.org/security/2011/dsa-2225 http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058922.html http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059702.html http://securitytracker.com/id?1025432 http://secunia.com/advisories/44197 http://secunia.com/advisories/44529 http://www.vupen.com/english/advisories/2011/1086 http://www.vupen.com/english/advisories/2011/1107 http://www.vupen.com/english/advisories/2011/1188 |
| Copyright | Copyright (c) 2011 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|