Secunia Logo
 
SUSE update for asterisk
Secunia Advisory: SA25582
Release Date: 2007-06-07
Popularity: 5,437 views

Critical:
Moderately critical
Impact: Exposure of sensitive information
DoS
Where: From remote
Solution Status: Vendor Patch

OS:openSUSE 10.2
SUSE Linux 10.1

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-1306
CVE-2007-1561
CVE-2007-1594
CVE-2007-1595
CVE-2007-2294
CVE-2007-2297
CVE-2007-2488


Description:
SUSE has issued an update for asterisk. This fixes some vulnerabilities, which can be exploited by malicious users to disclose potentially sensitive information or by malicious people to cause a DoS (Denial of Service).

For more information:
SA24380
SA24977
SA24564
SA24579
SA25134

Solution:
Apply updated packages.

x86 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/asterisk-1.2.13-23.i586.rpm
00b2cfd6b8ac2d7d433992b0b1443c11

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/asterisk-1.2.5-12.12.i586.rpm
de8d3bf81cf5ba905383e9d18e416185

Power PC Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/asterisk-1.2.13-23.ppc.rpm
c8d7b98b1a96e8aa212bc763c2e609ba

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/asterisk-1.2.5-12.12.ppc.rpm
2c7a49f6ccfc6098dfe721069cb6450f

x86-64 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/asterisk-1.2.13-23.x86_64.rpm
e293c4ca8f494925ede2b379ec5db220

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10...86_64/asterisk-1.2.5-12.12.x86_64.rpm
a54c6f445b9f5fb2bec9f73dd3c2235c

Sources:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/asterisk-1.2.13-23.src.rpm
a27514b489a70f9941eca06afc2f7c99

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/asterisk-1.2.5-12.12.src.rpm
205e2ec41fd07acf4cfb91ab152d2d90

Original Advisory:
http://lists.suse.com/archive/suse-security-announce/2007-Jun/0003.html

Other References:
SA24380:
http://secunia.com/advisories/24380/

SA24977:
http://secunia.com/advisories/24977/

SA24564:
http://secunia.com/advisories/24564/

SA24579:
http://secunia.com/advisories/24579/

SA25134:
http://secunia.com/advisories/25134/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 123 views
2. Microsoft Office Communications Server SIP INVITE Denial of Service // 80 views
3. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 68 views
4. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 64 views
5. Lito Lite CMS "cid" SQL Injection Vulnerability // 35 views
6. Bluo CMS "id" SQL Injection Vulnerability // 32 views
7. Mozilla Firefox 3 Multiple Vulnerabilities // 31 views
8. RakhiSoftware Shopping Cart Multiple Vulnerabilities // 27 views
9. Adobe Acrobat/Reader Multiple Vulnerabilities // 27 views
10. BlackBerry Desktop Software FlexNET Connect ActiveX Control Vulnerability // 27 views