Release date:
Updated on:
Affected Systems:
Asterisk Open Source 1.8.3.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57106
CVE (CAN) ID: CVE-2012-5976
Asterisk is a free open-source software that enables the Telephone User Switch (PBX) function.
Asterisk has multiple buffer overflow vulnerabilities when processing some SIP, HTTP, and XMPP network messages. Remote attackers can exploit this vulnerability to cause Asterisk to crash.
<* Source: Walter Doekes
Link: https://bugzilla.RedHat.com/show_bug.cgi? CVE-2012-5976
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asterisk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
[1] http://downloads.asterisk.org/pub/security/
[2] http://downloads.asterisk.org/pub/security/AST-2012-014-1.8.11.diff
[3] http://downloads.asterisk.org/pub/security/AST-2012-014-1.8.diff
[4] http://downloads.asterisk.org/pub/security/AST-2012-014-10.diff
[5] http://downloads.asterisk.org/pub/security/AST-2012-014-11.diff