Release date: 2011-10-18
Updated on: 2011-10-18
Affected Systems:
Asterisk Open Source 10.x
Asterisk Open Source 1.8.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-4063
Asterisk is a free and open-source software that enables the Telephone User Switch (PBX) function.
The Asterisk implementation has a denial of service vulnerability. Due to uninitialized variables, users remotely authenticated can cause a crash through malicious requests.
<* Source: Ehsan Foroughi
Link: http://seclists.org/bugtraq/2011/Oct/109
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asterisk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://downloads.asterisk.org/pub/security/