Release date:
Updated on:
Affected Systems:
Asterisk 10.4.1
Asterisk 10.3.1
Asterisk 10.3.0
Asterisk 10.2.1
Asterisk 10.2.0
Asterisk 10.0.1
Asterisk 10.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54017
Cve id: CVE-2012-3553
Asterisk is a free and open-source software that enables the Telephone User Switch (PBX) function.
Chan_skinny.c In the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.5.1 allows remote authenticated users to cause a denial of service by sending the Station Key Pad Button message and disabling connections in off-hook mode, leading to NULL pointer reference and program crash.
<* Source: Christoph Hebeisen
Link: http://secunia.com/advisories/49543/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asterisk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://downloads.asterisk.org/pub/security/