Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.70579
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2367-1 (asterisk)
Zusammenfassung:The remote host is missing an update to asterisk;announced via advisory DSA 2367-1.
Beschreibung:Summary:
The remote host is missing an update to asterisk
announced via advisory DSA 2367-1.

Vulnerability Insight:
Several vulnerabilities have been discovered in Asterisk, an Open
Source PBX and telephony toolkit:

CVE-2011-4597

Ben Williams discovered that it was possible to enumerate SIP
user names in some configurations.

This update only modifies the sample sip.conf configuration
file. Please see README.Debian for more information on how
to update your installation.

CVE-2011-4598

Kristijan Vrban discovered that Asterisk can be crashed with
malformed SIP packets if the automon feature is enabled.

For the oldstable distribution (lenny), this problem has been fixed in
version 1:1.4.21.2~
dfsg-3+lenny6.

For the stable distribution (squeeze), this problem has been fixed in
version 1:1.6.2.9-2+squeeze4.

For the unstable distribution (sid), this problem has been fixed in
version 1:1.8.8.0~
dfsg-1.

Solution:
We recommend that you upgrade your asterisk packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-4597
Bugtraq: 20111222 Exploit for Asterisk Security Advisory AST-2011-013 (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2011-12/0151.html
Debian Security Information: DSA-2367 (Google Search)
http://www.debian.org/security/2011/dsa-2367
http://lists.digium.com/pipermail/asterisk-dev/2011-November/052191.html
http://openwall.com/lists/oss-security/2011/12/09/3
http://openwall.com/lists/oss-security/2011/12/09/4
http://osvdb.org/77597
http://secunia.com/advisories/47273
Common Vulnerability Exposure (CVE) ID: CVE-2011-4598
http://osvdb.org/77598
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.