Welcome to Soft32 Linux Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Bug#552756: AST-2009-007: SIP INVITE ACL bypass

 
   Soft32 Home -> Linux -> Bugs RC RSS
Next:  Bug#525549: gnucash-dbg  
Author Message
Raphael Geissert

External


Since: Jul 03, 2009
Posts: 40



(Msg. 1) Posted: Wed Oct 28, 2009 11:20 pm
Post subject: Bug#552756: AST-2009-007: SIP INVITE ACL bypass
Archived from groups: linux>debian>bugs>rc (more info?)

Package: asterisk
Version: 1:1.6.2.0~dfsg~rc1-1
Severity: grave
Tags: security patch

Hi,

A vulnerability has been reported in asterisk that allows a device to make
calls on networks intended to be prohibited as defined by the "deny"
and "permit" lines in sip.conf.

The original advisory can be found at:
http://downloads.asterisk.org/pub/security/AST-2009-007.html

And the patch at:
http://downloads.asterisk.org/pub/security/AST-2009-007-1.6.1.diff.txt

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry, whenever one is assigned.

Cheers,
--
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net



--
To UNSUBSCRIBE, email to debian-bugs-rc-REQUEST RemoveThis @lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster RemoveThis @lists.debian.org
Back to top
Login to vote
Raphael Geissert

External


Since: Jul 03, 2009
Posts: 40



(Msg. 2) Posted: Thu Oct 29, 2009 11:20 am
Post subject: Bug#552756: AST-2009-007: SIP INVITE ACL bypass [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

2009/10/29 Faidon Liambotis <paravoid.DeleteThis@debian.org>:
> Raphael Geissert wrote:
>> Yes, the versions in testing and unstable (at least those that were
>> there before I reported it) were both affected. May I suggest you to
>> reply to the email in the future whenever you don't think it affects a
>> version? the versions in the descriptions are usually not exclusive
>> and should be treated as 'at least' (not much we can do, as it is
>> mitre who writes the descriptions).
> Reply to which email?

The bug report Wink

>
> And FWIW, Asterisk security advisories mention version numbers
> explicitelly and do not follow the "at least" rule.
>
> However, the version that we ship in unstable is a release candidate
> (rc3) for 1.6.2 and hence is not mentioned at all in those advisories.
> That was the source of the confusion.

Ah, right, sorry, I though the description came from the CVE (but
there's none assigned, to the best of my knowledge, yet).

Cheers,
--
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net



--
To UNSUBSCRIBE, email to debian-bugs-rc-REQUEST.DeleteThis@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster.DeleteThis@lists.debian.org
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Bug#435572: octave2.1-forge: the package cannot be install.. - Package: octave2.1-forge Severity: serious Justification: Policy 3.5 Hi, the package depends on libgsl0 which is no....

Bug#424445: Proposed patch for #424445 (turkey FTBFS) - I have used a slightly modified version of your patch in Ubuntu, and now thanks to you we also are able to compile for....

Bug#311188: (no subject) - I send some little pings to some of the bugs who can be easily fixed. For the syslogd stuff I would wait if joey..

Bug#435586: centerim-utf8: undeclared overlap with centerim - Package: centerim-utf8 Version: 4.22.1-1 Severity: serious Package does not install: Unpacking centerim-utf8 (from..

Bug#435600: apt-rpm_0.5.15lorg3.2-2(ia64/unstable): FTBFS:.. - Package: apt-rpm Version: 0.5.15lorg3.2-2 Severity: serious There was an error while trying to autobuild your package:...

[News] [Rival] 2009 Vista SP1 Release Rumour Still Alive, .. - [According to the latest, these patches were /leaked/, not released and the timeline looks grim] Vista Hotfix Packs..
       Soft32 Home -> Linux -> Bugs RC All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
 Windows
  Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]