Debian Security Advisory
DSA-2171-1 asterisk -- buffer overflow
- Date Reported:
- 21 Feb 2011
- Affected Packages:
- asterisk
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 610487.
In Mitre's CVE dictionary: CVE-2011-0495. - More information:
-
Matthew Nicholson discovered a buffer overflow in the SIP channel driver of Asterisk, an open source PBX and telephony toolkit, which could lead to the execution of arbitrary code.
For the oldstable distribution (lenny), this problem has been fixed in version 1.4.21.2~dfsg-3+lenny2.
For the stable distribution (squeeze), this problem has been fixed in version 1.6.2.9-2+squeeze1.
The unstable distribution (sid) will be fixed soon.
We recommend that you upgrade your asterisk packages.