MGASA-2014-0172
Dashboard / Vulnerabilities / MGASA-2014-0172
Summary: Updated asterisk packages fix security vulnerabilities
Details: Updated asterisk packages fix security vulnerabilities: In Asterisk before 11.8.1, sending a HTTP request that is handled by Asterisk with a large number of Cookie headers could overflow the stack. You could even exhaust memory if you sent an unlimited number of headers in the request (CVE-2014-2286). In Asterisk before 11.8.1, an attacker can use all available file descriptors using SIP INVITE requests. Each INVITE meeting certain conditions will leak a channel and several file descriptors. The file descriptors cannot be released without restarting Asterisk which may allow intrusion detection systems to be bypassed by sending the requests slowly (CVE-2014-2287).
References: https://advisories.mageia.org/MGASA-2014-0172.html, http://downloads.asterisk.org/pub/security/AST-2014-001.html, http://downloads.asterisk.org/pub/security/AST-2014-002.html, https://bugs.mageia.org/show_bug.cgi?id=13061
Affected packages
Package
Name: asterisk
Purl: pkg:rpm/mageia/asterisk?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
