Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.71262
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2460-1 (asterisk)
Zusammenfassung:The remote host is missing an update to asterisk;announced via advisory DSA 2460-1.
Beschreibung:Summary:
The remote host is missing an update to asterisk
announced via advisory DSA 2460-1.

Vulnerability Insight:
Several vulnerabilities were discovered in the Asterisk PBX and telephony
toolkit:

CVE-2012-1183

Russell Bryant discovered a buffer overflow in the Milliwatt
application.

CVE-2012-2414

David Woolley discovered a privilege escalation in the Asterisk
manager interface.

CVE-2012-2415

Russell Bryant discovered a buffer overflow in the Skinny driver.

For the stable distribution (squeeze), this problem has been fixed in
version 1:1.6.2.9-2+squeeze5.

For the unstable distribution (sid), this problem will be fixed soon.

Solution:
We recommend that you upgrade your asterisk packages.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-1183
BugTraq ID: 52523
http://www.securityfocus.com/bid/52523
Bugtraq: 20120315 AST-2012-002: Remote Crash Vulnerability in Milliwatt Application (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2012-03/0069.html
Debian Security Information: DSA-2460 (Google Search)
http://www.debian.org/security/2012/dsa-2460
http://www.openwall.com/lists/oss-security/2012/03/16/10
http://www.openwall.com/lists/oss-security/2012/03/16/17
http://osvdb.org/80125
http://securitytracker.com/id?1026812
http://secunia.com/advisories/48417
http://secunia.com/advisories/48941
XForce ISS Database: asterisk-milliwattgenerate-dos(74082)
https://exchange.xforce.ibmcloud.com/vulnerabilities/74082
Common Vulnerability Exposure (CVE) ID: CVE-2012-2414
BugTraq ID: 53206
http://www.securityfocus.com/bid/53206
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079759.html
http://osvdb.org/81454
http://www.securitytracker.com/id?1026961
http://secunia.com/advisories/48891
XForce ISS Database: asterisk-originate-command-exec(75100)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75100
Common Vulnerability Exposure (CVE) ID: CVE-2012-2415
BugTraq ID: 53210
http://www.securityfocus.com/bid/53210
http://osvdb.org/81455
http://www.securitytracker.com/id?1026962
XForce ISS Database: asterisk-skinny-driver-bo(75102)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75102
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.