First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 218966
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Rajiv Aaron Manglani <rajiv@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 218966 depends on: 249573 Show dependency tree
Bug 218966 blocks: 232696

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-04-22 23:16 0000
http://lists.digium.com/pipermail/asterisk-announce/2008-April/000139.html


[asterisk-announce] Asterisk 1.2.28, 1.4.19.1, and 1.6.0-beta8 Released
The Asterisk Development Team asteriskteam at digium.com
Tue Apr 22 18:05:07 CDT 2008

The Asterisk development team has released versions 1.2.28, 1.4.19.1, and
1.6.0-beta8.

All of these releases contain a security patch for the vulnerability described
in the AST-2008-006 security advisory.  1.6.0-beta8 is also a regular update to
the 1.6.0 series with a number of bug fixes over the previous beta release.

Early last year, we made some modifications to the IAX2 channel driver to
combat
potential usage of IAX2 in traffic amplification attacks.  Unfortunately, our
fix was not complete and we were not notified of this until the original
reporter of the issue decided to release information on how to exploit it to
the
public.

This issue affects all users of IAX2 that have allowed non-authenticated calls.
 For more information on the vulnerability, see the published security
advisory.

 * http://downloads.digium.com/pub/security/AST-2008-006.pdf

All releases are available for download from the following location:

 * http://downloads.digium.com/pub/telephony/asterisk/

Thank you for your continued support of Asterisk!





Javantea originally reported an issue in IAX2, whereby an attacker could send a
spoofed IAX2 NEW message, and Asterisk would start sending early audio to the
target address, without ever receiving an initial response. That original
vulnerability was addressed in June 2007, by requiring a response to the
initial NEW message before starting to send any audio.


Javantea subsequently found that we were doing insufficent verification of the
ACK response and that the ACK response could be spoofed, just like the initial
NEW message. We have addressed this failure with two changes. First, we have
started to require that the ACK response contains the unique source call number
that we send in our reply to the NEW message. Any ACK response that does not
contain the source call number that we have created will be silently thrown
away. Second, we have made the generation of our source call number a little
more difficult to predict, by randomly selecting a source call number, instead
of allocating them sequentially.

------- Comment #1 From Rambaldi 2008-04-23 07:00:41 0000 -------
fixed in voip overlay for versions 1.4.19.1 and 1.6.0-beta8. 

------- Comment #2 From Robert Buchholz 2008-04-23 22:15:03 0000 -------
CVE-2008-1923 was assigned to the original "NEW" issue in June 2007.

------- Comment #3 From Robert Buchholz 2008-04-23 22:27:19 0000 -------
(In reply to comment #2)
> CVE-2008-1923 was assigned to the original "NEW" issue in June 2007.

This was released with 1.2.20.

------- Comment #4 From Pierre-Yves Rofes 2008-05-11 13:20:11 0000 -------
voip, any news here?

------- Comment #5 From Anton Bolshakov 2008-12-15 05:19:43 0000 -------
This is only first security bug report from 7 others opened.
Somebody has either mask asterisk stable packages in the portage or fix them
all.

The way how it is now doesn't make sense for me.

------- Comment #6 From Rajiv Aaron Manglani 2009-03-12 03:33:19 0000 -------
+*asterisk-1.2.31.1 (11 Mar 2009)
+
+  11 Mar 2009; <chainsaw@gentoo.org>
+  +files/1.2.0/asterisk-1.2.31.1-bri-fixups.diff,
+  +files/1.2.0/asterisk-1.2.31.1-comma-is-not-pipe.diff,
+  +files/1.2.0/asterisk-1.2.31.1-svn89254.diff, +asterisk-1.2.31.1.ebuild:
+  Version bump, for security bugs #250748 and #254304. Took a 1.4 build fix
+  that is relevant to 1.2, Digium bug #11238. Wrote patch to fix up typo in
+  open call, a comma is not a pipe sign. Used EAPI 2 for USE-based
+  dependencies instead of calling die. Patch from Mounir Lamouri adding
+  -lspeexdsp closes bug #206463 filed by John Read.

------- Comment #7 From Alex Legler 2009-03-12 15:34:40 0000 -------
Stabling via bug 250748

------- Comment #8 From Robert Buchholz 2009-05-02 17:57:29 0000 -------
GLSA 200905-01

First Last Prev Next    No search results available      Search page      Enter new bug