~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
Candidate: CVE-2011-2216
PublicDate: 2011-06-06
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2216
 http://downloads.digium.com/pub/security/AST-2011-007.html
Description:
 reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x
 before 1.8.4.2 does not initialize certain strings, which allows remote
 attackers to cause a denial of service (NULL pointer dereference and daemon
 crash) via a malformed Contact header.
Ubuntu-Description:
Notes:
 mdeslaur> may be 1.8.x only, need to check
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_asterisk:
 upstream: Http://downloads.asterisk.org/pub/security/AST-2011-007-1.8.diff
upstream_asterisk: released (1.8.4.2)
hardy_asterisk: ignored (reached end-of-life)
lucid_asterisk: not-affected (1:1.6.2.5-0ubuntu1.3)
maverick_asterisk: not-affected (1:1.6.2.7-1ubuntu1.1)
natty_asterisk: not-affected (1:1.6.2.9-2ubuntu2)
oneiric_asterisk: not-affected (1:1.8.4.4~dfsg-2ubuntu1)
precise_asterisk: not-affected (1:1.8.10.1~dfsg-1ubuntu1)
quantal_asterisk: not-affected (1:1.8.10.1~dfsg-1ubuntu1)
devel_asterisk: not-affected (1:1.8.10.1~dfsg-1ubuntu1)