Summary: | <net-misc/asterisk-{1.8.12.1,10.4.1} Skinny Remote Crash Vulnerability (CVE-2012-2948) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Rajiv Aaron Manglani (RETIRED) <rajiv> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | voip+disabled |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://downloads.digium.com/pub/security/AST-2012-008.html | ||
Whiteboard: | B2 [glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 418189 | ||
Bug Blocks: |
Description
Rajiv Aaron Manglani (RETIRED)
![]() Stabilization happening in bug 418189. CVE-2012-2948 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2948): chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by closing a connection in off-hook mode. This issue was resolved and addressed in GLSA 201206-05 at http://security.gentoo.org/glsa/glsa-201206-05.xml by GLSA coordinator Sean Amoss (ackle). |