NASLDB: Fedora 14 : asterisk-1.6.2.19-1.fc14 (2011-8914)
General
ID: 55581
Name: Fedora 14 : asterisk-1.6.2.19-1.fc14 (2011-8914)
Summary: Checks rpm output for the updated package
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS Temporal Vector: –
Port: 0
Family: Fedora Local Security Checks
Type: Local
Description
The Asterisk Development Team has announced the final maintenance
release of Asterisk, version 1.6.2.19. This release is available for
immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk/
Please note that Asterisk 1.6.2.19 is the final maintenance release
from the 1.6.2 branch. Support for security related issues will
continue until April 21, 2012. For more information about support of
the various Asterisk branches, see
https://wiki.asterisk.org/wiki/display/AST/Asterisk+Versions
The release of Asterisk 1.6.2.19 resolves several issues reported by
the community and would have not been possible without your
participation. Thank you!
The following is a sample of the issues resolved in this release :
– Don’t broadcast FullyBooted to every AMI connection The
FullyBooted event should not be sent to every AMI
connection every time someone connects via AMI. It
should only be sent to the user who just connected.
(Closes issue #18168. Reported, patched by FeyFre)
– Fix thread blocking issue in the sip TCP/TLS
implementation. (Closes issue #18497. Reported by vois.
Tested by vois, rossbeer, kowalma, Freddi_Fonet. Patched
by dvossel)
– Don’t delay DTMF in core bridge while listening for DTMF
features. (Closes issue #15642, #16625. Reported by
jasonshugart, sharvanek. Tested by globalnetinc, jde.
Patched by oej, twilson)
– Fix chan_local crashs in local_fixup() Thanks OEJ for
tracking down the issue and submitting the patch.
(Closes issue #19053. Reported, patched by oej)
– Don’t offer video to directmedia callee unless caller
offered it as well (Closes issue #19195. Reported,
patched by one47)
Additionally security announcements AST-2011-008, AST-2011-010, and
AST-2011-011 have been resolved in this release.
For a full list of changes in this release, please see the ChangeLog :
http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.1
9 The Asterisk Development Team has announced the release of Asterisk
versions 1.4.41.1, 1.6.2.18.1, and 1.8.4.3, which are security
releases.
These releases are available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk/releases
The release of Asterisk 1.4.41.1, 1.6.2.18, and 1.8.4.3 resolves
several issues as outlined below :
– AST-2011-008: If a remote user sends a SIP packet
containing a null, Asterisk assumes available data
extends past the null to the end of the packet when the
buffer is actually truncated when copied. This causes
SIP header parsing to modify data past the end of the
buffer altering unrelated memory structures. This
vulnerability does not affect TCP/TLS connections. —
Resolved in 1.6.2.18.1 and 1.8.4.3
– AST-2011-009: A remote user sending a SIP packet
containing a Contact header with a missing left angle
bracket (<) causes Asterisk to access a null pointer. —
Resolved in 1.8.4.3
– AST-2011-010: A memory address was inadvertently
transmitted over the network via IAX2 via an option
control frame and the remote party would try to access
it. — Resolved in 1.4.41.1, 1.6.2.18.1, and 1.8.4.3
The issues and resolutions are described in the AST-2011-008,
AST-2011-009, and AST-2011-010 security advisories.
For more information about the details of these vulnerabilities,
please read the security advisories AST-2011-008, AST-2011-009, and
AST-2011-010, which were released at the same time as this
announcement.
For a full list of changes in the current releases, please see the
ChangeLog :
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLo
g-1.4.41.1
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLo
g-1.6.2.18.1
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLo
g-1.8.4.3
Security advisories AST-2011-008, AST-2011-009, and AST-2011-010 are
available at :
http://downloads.asterisk.org/pub/security/AST-2011-008.pdf
http://downloads.asterisk.org/pub/security/AST-2011-009.pdf
http://downloads.asterisk.org/pub/security/AST-2011-010.pdf
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2011-2529
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: 2011/06/30
Plugin Release: 2011/07/13
Plugin
Version: 1.3
Filename: fedora_2011-8914.nasl
Filesize: 8334 bytes
MD5 Hash: 96854331e62e6d070af41e4953c2ae0e
Identification: Host/local_checks_enabled
Require Keys: Host/local_checks_enabled", "Host/RedHat/release", "Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2011-2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













