Executive Summary

Summary
Titleasterisk security update
Informations
NameDSA-2460First vendor Publication2012-04-25
VendorDebianLast vendor Modification2012-04-25
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:P)
Cvss Base Score6.5Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityLow
Cvss Expoit Score8AuthentificationRequires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities were discovered in the Asterisk PBX and telephony toolkit:

CVE-2012-1183

Russell Bryant discovered a buffer overflow in the Milliwatt application.

CVE-2012-2414

David Woolley discovered a privilege escalation in the Asterisk manager interface.

CVE-2012-2415

Russell Bryant discovered a buffer overflow in the Skinny driver.

For the stable distribution (squeeze), this problem has been fixed in version 1:1.6.2.9-2+squeeze5.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your asterisk packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2460

CWE : Common Weakness Enumeration

idName
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
CWE-287Improper Authentication

CPE : Common Platform Enumeration

TypeDescriptionCount
Application153
Application349