[Bug 1022360]
Glsamaker
1022360 at bugs.launchpad.net
Thu Jul 12 01:07:14 UTC 2012
CVE-2012-3863 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3863):
channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x
before 10.5.2, Asterisk Business Edition C.3.x before C.3.7.5, Certified
Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones
10.x.x-digiumphones before 10.5.2-digiumphones does not properly handle a
provisional response to a SIP reINVITE request, which allows remote
authenticated users to cause a denial of service (RTP port exhaustion) via
sessions that lack final responses.
--
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to asterisk in Ubuntu.
https://bugs.launchpad.net/bugs/1022360
Title:
(CVE-2012-3812) CVE-2012-3812 asterisk: Remote crash vulnerability in
voice mail application (CVE-2012-3863) CVE-2012-3863 asterisk:
Possible resource leak on uncompleted re-invite transactions
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/asterisk/+bug/1022360/+subscriptions
More information about the Ubuntu-server-bugs
mailing list