Bug 269387 - VUL-0: Multiple security holes in Asterisk
VUL-0: Multiple security holes in Asterisk
Status: RESOLVED FIXED
: 267826 (view as bug list)
Classification: openSUSE
Product: openSUSE 10.2
Classification: openSUSE
Component: Security
Final
Other Other
: P5 - None : Normal (vote)
: ---
Assigned To: Security Team bot
E-mail List
CVE-2007-2297: CVSS v2 Base Score: 7....
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2007-04-27 16:36 UTC by Martin Jürgens
Modified: 2009-10-13 23:16 UTC (History)
4 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Jürgens 2007-04-27 16:36:52 UTC
Multiple security holes have been fixed in Asterisk 1.2.18.

These are:

http://lists.grok.org.uk/pipermail/full-
disclosure/2007-April/053969.html

http://lists.grok.org.uk/pipermail/full-
disclosure/2007-April/053967.html

http://lists.grok.org.uk/pipermail/full-
disclosure/2007-April/053968.html
Comment 1 Martin Jürgens 2007-04-27 17:02:38 UTC
ASA-2007-010 only applys for 1.4


http://svn.digium.com/view/asterisk/branches/1.2/channels/chan_sip.c?r1=58847&r2=59194 fixes ASA-2007-011

http://svn.digium.com/view/asterisk/branches/1.2/manager.c?r1=60134&r2=61786 fixes ASA-2007-012
Comment 3 Ludwig Nussel 2007-05-02 08:18:06 UTC
Thanks for the links. The issues that affect asterisk version we ship are just DoS bugs AFAICS so they are not that urgent. Reassigning to maintainer.
Comment 4 Ludwig Nussel 2007-05-02 08:18:39 UTC
*** Bug 267826 has been marked as a duplicate of this bug. ***
Comment 5 Reinhard Max 2007-05-02 16:25:40 UTC
ASA-2007-011 is CVE-2007-2297
ASA-2007-012 is CVE-2007-2294
Comment 6 Reinhard Max 2007-05-02 17:43:10 UTC
Patched package submitted to 10.1 and 10.2.
Comment 7 Ludwig Nussel 2007-05-31 09:20:25 UTC
tracked in #251177
Comment 8 Marcus Meissner 2007-06-06 13:41:41 UTC
finally released the updates.
Comment 9 Thomas Biege 2009-10-13 23:16:16 UTC
CVE-2007-2297: CVSS v2 Base Score: 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)