|
Asterisk IAX2 Channel Driver Information Disclosure
|
|
Secunia Advisory:
|
SA25134
|
|
|
Release Date:
|
2007-05-07
|
|
Popularity:
|
7,608 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Exposure of sensitive information
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Workaround
|
|
| Software: | Asterisk 1.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: A vulnerability has been reported in Asterisk, which can be exploited by malicious users to disclose potential sensitive information.
The vulnerability is caused due to an error within the IAX2 channel driver (chan_iax2) in the processing of text frames. This can be exploited to disclose potentially sensitive heap memory by sending a text frame with content that is not NULL terminated.
The vulnerability affects the following versions:
* Asterisk Open Source 1.2.x and 1.4.x (all releases prior 1.2.19 and 1.4.5)
* Asterisk Business Edition A.x.x (all releases)
* Asterisk Business Edition B.x.x (all releases prior to B.2.1)
* AsteriskNOW pre-release (all releases prior to and including Beta 5)
* Asterisk Appliance Developer Kit (all releases prior to 0.4.1)
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|