Asterisk Format String Bug in Logger and Manager Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1019630
|
|
SecurityTracker URL: http://securitytracker.com/id?1019630
|
|
CVE Reference: CVE-2008-1333
(Links to External Site)
|
Date: Mar 18 2008
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 1.6.x, prior to 1.6.0-beta6
|
Description: A vulnerability was reported in Asterisk in the Logger and Manager functions. A remote user can cause denial of service conditions.
The ast_verbose logging API call does not properly display data. A remote user can provide a format string value so that when the
Manager 'command' command is invoked by a target user, the application will crash.
The vendor was notified on March 13, 2008.
Steve
Davies and Brandon Kruse reported this vulnerability.
|
Impact: A remote user can cause the application to crash.
|
Solution: The vendor has issued a fixed version (1.6.0-beta6), available at:
http://downloads.digium.com/pub/telephony/asterisk
|
Vendor URL: downloads.digium.com/pub/security/AST-2008-004.html (Links to External Site)
|
Cause: Input validation error, State error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 18 Mar 2008 14:41:37 -0500
Subject: Asterisk Project Security Advisory - AST-2008-004
|
http://downloads.digium.com/pub/security/AST-2008-004.html
|
|