Executive Summary
| Summary | |
|---|---|
| Title | Asterisk: Multiple vulnerabilities |
| Informations | |||
|---|---|---|---|
| Name | GLSA-201203-21 | First vendor Publication | 2012-03-28 |
| Vendor | Gentoo | Last vendor Modification | 2012-03-28 |
| Severity (Vendor) | High | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 7.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Synopsis Multiple vulnerabilities have been found in Asterisk, the worst of which may allow execution of arbitrary code. Background Asterisk is an open source telephony engine and toolkit. Description Two vulnerabilities have been found in Asterisk: * The "milliwatt_generate()" function in app_milliwatt.c is vulnerable to a stack overrun (AST-2012-002). * The "ast_parse_digest()" function in utils.c is vulnerable to a stack-based buffer overflow (AST-2012-003). Impact A remote unauthenticated attacker could execute arbitrary code or cause a Denial of Service condition. Workaround There is no known workaround at this time. Resolution All Asterisk users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.8.10.1" References [ 1 ] AST-2012-002 http://downloads.asterisk.org/pub/security/AST-2012-002.txt [ 2 ] AST-2012-003 http://downloads.asterisk.org/pub/security/AST-2012-003.txt [ 3 ] CVE-2012-1183 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1183 [ 4 ] CVE-2012-1184 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1184 Availability This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201203-21.xml |
Original Source
| Url : http://security.gentoo.org/glsa/glsa-201203-21.xml |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |

GLSA-201203-21
(High)
(Medium)




