Asterisk PJSIP Channel Driver Denial of Service Vulnerability (CVE-2014-4048)
Release date:
Updated on:
Affected Systems:
Asterisk <12.3.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68032
CVE (CAN) ID: CVE-2014-4048
Asterisk is a free and open-source software that enables the Telephone User Switch (PBX) function.
Asterisk earlier than 12.3.1 has a remote denial-of-service vulnerability. Attackers can exploit this vulnerability to cause the affected applications to crash, resulting in DOS.
Install Asterisk In Ubuntu 12.10
<* Source: Mark Michelin (mmichelson@digium.com)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asterisk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://downloads.asterisk.org/pub/security/
This article permanently updates the link address: