Debian Security Advisory

DSA-2171-1 asterisk -- buffer overflow

Date Reported:
21 Feb 2011
Affected Packages:
asterisk
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 610487.
In Mitre's CVE dictionary: CVE-2011-0495.
More information:

Matthew Nicholson discovered a buffer overflow in the SIP channel driver of Asterisk, an open source PBX and telephony toolkit, which could lead to the execution of arbitrary code.

For the oldstable distribution (lenny), this problem has been fixed in version 1.4.21.2~dfsg-3+lenny2.

For the stable distribution (squeeze), this problem has been fixed in version 1.6.2.9-2+squeeze1.

The unstable distribution (sid) will be fixed soon.

We recommend that you upgrade your asterisk packages.