Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71262
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2460-1)
Summary:The remote host is missing an update for the Debian 'asterisk' package(s) announced via the DSA-2460-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'asterisk' package(s) announced via the DSA-2460-1 advisory.

Vulnerability Insight:
Several vulnerabilities were discovered in the Asterisk PBX and telephony toolkit:

CVE-2012-1183

Russell Bryant discovered a buffer overflow in the Milliwatt application.

CVE-2012-2414

David Woolley discovered a privilege escalation in the Asterisk manager interface.

CVE-2012-2415

Russell Bryant discovered a buffer overflow in the Skinny driver.

For the stable distribution (squeeze), this problem has been fixed in version 1:1.6.2.9-2+squeeze5.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your asterisk packages.

Affected Software/OS:
'asterisk' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1183
1026812
http://securitytracker.com/id?1026812
20120315 AST-2012-002: Remote Crash Vulnerability in Milliwatt Application
http://archives.neohapsis.com/archives/bugtraq/2012-03/0069.html
48417
http://secunia.com/advisories/48417
48941
http://secunia.com/advisories/48941
52523
http://www.securityfocus.com/bid/52523
80125
http://osvdb.org/80125
DSA-2460
http://www.debian.org/security/2012/dsa-2460
[oss-security] 20120316 CVE Request -- Asterisk: AST-2012-002 and AST-2012-003 flaws
http://www.openwall.com/lists/oss-security/2012/03/16/10
[oss-security] 20120316 Re: CVE Request -- Asterisk: AST-2012-002 and AST-2012-003 flaws
http://www.openwall.com/lists/oss-security/2012/03/16/17
asterisk-milliwattgenerate-dos(74082)
https://exchange.xforce.ibmcloud.com/vulnerabilities/74082
http://downloads.asterisk.org/pub/security/AST-2012-002-1.8.diff
http://downloads.asterisk.org/pub/security/AST-2012-002.pdf
http://www.asterisk.org/node/51797
Common Vulnerability Exposure (CVE) ID: CVE-2012-2414
BugTraq ID: 53206
http://www.securityfocus.com/bid/53206
Debian Security Information: DSA-2460 (Google Search)
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079759.html
http://osvdb.org/81454
http://www.securitytracker.com/id?1026961
http://secunia.com/advisories/48891
XForce ISS Database: asterisk-originate-command-exec(75100)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75100
Common Vulnerability Exposure (CVE) ID: CVE-2012-2415
BugTraq ID: 53210
http://www.securityfocus.com/bid/53210
http://osvdb.org/81455
http://www.securitytracker.com/id?1026962
XForce ISS Database: asterisk-skinny-driver-bo(75102)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75102
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.