Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 373409 - <net-misc/asterisk-{1.6.2.18.2,1.8.4.4}: Information disclosure AST-2011-011 (CVE-2011-{2536,2665,2666})
Summary: <net-misc/asterisk-{1.6.2.18.2,1.8.4.4}: Information disclosure AST-2011-011 ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL: http://www.asterisk.org/node/51653
Whiteboard: B1 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-06-28 21:47 UTC by Tony Vroon (RETIRED)
Modified: 2011-10-24 18:46 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tony Vroon (RETIRED) gentoo-dev 2011-06-28 21:47:08 UTC
Asterisk may respond differently to SIP requests from an invalid SIP user than it does to a user configured on the system, even when the alwaysauthreject option is set in the configuration. This can leak information about what SIP users are valid on the Asterisk system.

1.4 branch: Not in portage.
1.6.2 branch: Ebuilds in tree, need stable keywords.
1.8 branch: In portage, vulnerable ebuilds axed, no stable keywords.

Arches, please test & stable 1.6.2.18.2. Suggested test procedure is to install
the daemon with the default configs and to stop/start the daemon multiple
times.
Comment 1 Agostino Sarubbo gentoo-dev 2011-06-28 22:04:53 UTC
it works!
Comment 2 Kenneth Prugh (RETIRED) gentoo-dev 2011-06-28 22:09:53 UTC
amd64 stable, thanks Agostino!
Comment 3 Andreas Schürch gentoo-dev 2011-06-29 05:51:28 UTC
=net-misc/asterisk-1.6.2.18.2 seems good here on x86.
Comment 4 Markus Meier gentoo-dev 2011-06-29 19:04:22 UTC
x86 stable, thanks Andreas. All arches done.
Comment 5 Tony Vroon (RETIRED) gentoo-dev 2011-06-29 19:16:12 UTC
+  29 Jun 2011; Tony Vroon <chainsaw@gentoo.org> -asterisk-1.6.2.18.1.ebuild:
+  Remove last vulnerable ebuild in 1.6.2 branch now that stabling has been
+  completed. For security bug #373409.
Comment 6 Tim Sammut (RETIRED) gentoo-dev 2011-06-29 21:40:21 UTC
Thanks, folks. Added to existing GLSA request.
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2011-10-24 18:46:03 UTC
This issue was resolved and addressed in
 GLSA 201110-21 at http://security.gentoo.org/glsa/glsa-201110-21.xml
by GLSA coordinator Tim Sammut (underling).