<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>169616</bug_id>
          
          <creation_ts>2007-03-06 13:43 0000</creation_ts>
          <short_desc>net-misc/asterisk: SIP DoS vulnerability (CVE-2007-1306)</short_desc>
          <delta_ts>2007-03-17 06:51:34 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://asterisk.org/node/48319</bug_file_loc>
          <status_whiteboard>B3 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>chainsaw@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bernd@linx.net</cc>
    
    <cc>rajiv@gentoo.org</cc>
    
    <cc>voip@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>chainsaw@gentoo.org</who>
            <bug_when>2007-03-06 13:43:47 0000</bug_when>
            <thetext>&quot;This release contains a number of bug fixes, including a fix for a recently discovered security vulnerability. All Asterisk 1.2 users are urged to update to this release as soon as possible.&quot;

Similar story for the asterisk 1.4 branch, please update to 1.4.1 there.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2007-03-06 14:17:22 0000</bug_when>
            <thetext>stkn/voip-herd, please provide an updated ebuild</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rajiv@gentoo.org</who>
            <bug_when>2007-03-06 16:58:36 0000</bug_when>
            <thetext>asterisk 1.0.12 is also vulnerable but not supported upstream. i will patch in our cvs shortly.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-06 22:58:10 0000</bug_when>
            <thetext>*** Bug 169681 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rajiv@gentoo.org</who>
            <bug_when>2007-03-09 20:30:03 0000</bug_when>
            <thetext>net-misc/asterisk-1.0.12-r1 with ported patch in cvs as ~x86 and ~ppc.

x86 team: please test and mark stable (or drop me an email and i will do it).

older 1.0.12 version is ~ppc also so nothing to be done there.

fyi, vulnerability notice: http://labs.musecurity.com/advisories/MU-200703-01.txt
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-09 21:14:29 0000</bug_when>
            <thetext>Just as a reminder, 1.2.* needs to be fixed too

Secunia says 1.2.16 fixes that vulnerability

Secunia: http://secunia.com/advisories/24380/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-10 14:13:05 0000</bug_when>
            <thetext>rajiv, please bump 1.2.* too, so we can stabilize both.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-03-12 19:12:34 0000</bug_when>
            <thetext>Rajiv just handles the 1.0 branch.
I can handle 1.2 but i&apos;m waiting for a newer upstream (http://www.junghanns.net/downloads/) BRIstuff patch since PRE-1y isn&apos;t 1.2.16-friendly.
Otherwise we could just try to patch the offending code in asterisk and do a revbump.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-03-12 19:29:19 0000</bug_when>
            <thetext>(In reply to comment #7)
&gt; Rajiv just handles the 1.0 branch.
&gt; I can handle 1.2 but i&apos;m waiting for a newer upstream
&gt; (http://www.junghanns.net/downloads/) BRIstuff patch since PRE-1y isn&apos;t
&gt; 1.2.16-friendly.
&gt; Otherwise we could just try to patch the offending code in asterisk and do a
&gt; revbump.

 Maybe the best solution if you can&apos;t tell how long the newer patch may take to be provided.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-12 20:34:55 0000</bug_when>
            <thetext>Debian appears to have a BRIstuff PRE-1x patch for 1.2.16 if it&apos;s any help. Otherwise just a simple patch similar to the one for 1.0 branch would be fine.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rajiv@gentoo.org</who>
            <bug_when>2007-03-12 21:10:17 0000</bug_when>
            <thetext>fyi the original patch for 1.2.x and 1.4.x is available at http://svn.digium.com/view/asterisk?rev=57478&amp;view=rev
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-03-13 18:41:15 0000</bug_when>
            <thetext>Actually it&apos;s r57475 for asterisk-1.2 (r57478 is for 1.4).
Committed in asterisk-1.2.14-r1.
Will need =net-libs/libpri-1.2.4-r1 and =net-misc/zaptel-1.2.12-r1 stable with this too to match BRIstuff.
sparc stable btw.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-13 19:40:59 0000</bug_when>
            <thetext>Thanks Gustavo.

x86 please test and mark stable:
net-misc/asterisk-1.2.14-r1
net-libs/libpri-1.2.4-r1
net-misc/zaptel-1.2.12-r1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-03-13 19:58:09 0000</bug_when>
            <thetext>(In reply to comment #12)
&gt; Thanks Gustavo.
&gt; 
&gt; x86 please test and mark stable:
&gt; net-misc/asterisk-1.2.14-r1
&gt; net-libs/libpri-1.2.4-r1
&gt; net-misc/zaptel-1.2.12-r1

And 1.0.12-r1, too. Done.

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-15 22:10:44 0000</bug_when>
            <thetext>I vote yes for that VoIP platform for which disponibility is important.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-16 08:00:18 0000</bug_when>
            <thetext>Let&apos;s have a GLSA on this one.

GLSA drafted and ready for review.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-17 06:51:34 0000</bug_when>
            <thetext>GLSA 200703-14</thetext>
          </long_desc>
      
    </bug>

</bugzilla>