[asterisk] [CVE-2008-1897] DoS vulnerability
Bug #227299 reported by
disabled.user
This bug report is a duplicate of:
Bug #220849: AST-2008-006 - 3-way handshake in IAX2 incomplete.
Edit
Remove
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
asterisk (Ubuntu) |
New
|
Undecided
|
Unassigned | ||
Hardy |
New
|
Undecided
|
Unassigned | ||
Intrepid |
New
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: asterisk
References:
DSA-1563-1 (http://
Quoting:
"Joel R. Voss discovered that the IAX2 module of Asterisk, a free
software PBX and telephony toolkit performs insufficient validation of
IAX2 protocol messages, which may lead to denial of service."
CVE References
To post a comment you must log in.