|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200606-15] Asterisk: IAX2 video frame buffer overflow Vulnerability Assessment Details
|
[GLSA-200606-15] Asterisk: IAX2 video frame buffer overflow |
||
Asterisk: IAX2 video frame buffer overflow Detailed Explanation for this Vulnerability Assessment The remote host is affected by the vulnerability described in GLSA-200606-15 (Asterisk: IAX2 video frame buffer overflow) Asterisk fails to properly check the length of truncated video frames in the IAX2 channel driver which results in a buffer overflow. Impact A possible hacker could exploit this vulnerability by sending a specially crafted IAX2 video stream resulting in the execution of arbitrary code with the permissions of the user running Asterisk. Workaround Disable public IAX2 support. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2898 http://www.coresecurity.com/common/showdoc.php?idx=547&idxseccion=10 Solution: All Asterisk users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/asterisk-1.0.11_p1" Network Security Threat Level: High Networks Security ID: Vulnerability Assessment Copyright: (C) 2006 Michel Arboi |
||
Cables, Connectors |
Dell PowerEdge R720 Server - 2x8c CPU,256Gb RAM, 128Gb SSD/3x600Gb SAS, Proxmox
$340.00
DELL PowerEdge R730XD 24x 2.5" Server Dual 750W Dual Heatsink - BareBones TESTED
$299.99
Dell PowerEdge R630 8SFF 2.6Ghz 20-Core 128GB Mem 4x1G RJ-45 NIC 2x750W PSU
$399.04
Supermicro 4U 36 Bay Storage Server 2.4Ghz 8-C 128GB 1x1280W Rails TrueNAS ZFS
$721.06
INTEL XEON GOLD 6148 20 Core SR3B6 2.4GHZ 27.5MB Processor @24
$99.99
Intel Xeon Gold 6140 SR3AX 2.3GHz 18-Core Processor CPU
$39.99
Intel Xeon Gold 6138 2.0GHz 27.5MB 20-Core 125W LGA3647 SR3B5
$46.00
Intel Xeon E5-2690V2 3.00GHz 10-Core (SR1A5) Processor CPU READ DESCRIPTION
$12.00
HP Workstation Z640 2x Xeon E5-2623V4 32GB Ram 512 SSD Quadro K420 Linux GA
$243.59
Dell Precision 5810 Tower Intel Xeon E5-1603v3 2.8GHz 8GB RAM 500GB HDD W10P GPU
$129.99
|
||
No Discussions have been posted on this vulnerability. |