Release date:
Updated on:
Affected Systems:
Asterisk 1.x
Asterisk Certified Asterisk 1.8.11-cert1
Unaffected system:
Asterisk 10.4.1
Asterisk 1.8.12.1
Asterisk Certified Asterisk 1.8.11-cert2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53722
Cve id: CVE-2012-2947
Asterisk is a free and open-source software that enables the Telephone User Switch (PBX) function.
Asterisk has a security vulnerability in the implementation of the IAX2 channel driver. After MOH is enabled, the AST_CONTROL_HOLD structure cannot pass through empty data, causing application crash.
<* Source: mgrobecker
Link: https://issues.asterisk.org/jira/browse/ASTERISK-19597
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asterisk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://downloads.asterisk.org/pub/security/