Digium ha avisado de 3 problemas de seguridad de Asterisk
Ser谩n puestos
aqu铆
Se recomienda encarecidamente actualizar a 1.2.18 y 1.4.3 respectivamente.
Estos fallos son:
Remote Crash Vulnerability in Manager Interface
The Asterisk Manager Interface has a remote crash
vulnerability. If a manager user is configured in
manager.conf without a password, and then a connection
is made that attempts to use that username and MD5
authentication, Asterisk will dereference a NULL pointer
and crash.
Versiones Afectadas:
Asterisk Open Source 1.0.x All versions
Asterisk Open Source 1.2.x All versions prior to 1.2.18
Asterisk Open Source 1.4.x All versions prior to 1.4.3
Asterisk Business Edition A.x.x All versions
Asterisk Business Edition B.x.x All versions up to and including B.1.3
AsteriskNOW pre-release All version up to and including Beta5
Asterisk Appliance Developer0.x.x All versions prior to 0.4.0
Multiple problems in SIP channel parser handling response codes
Multiple problems have been identified in the Asterisk
SIP channel driver (chan_sip) when handling response
packets from other SIP endpoints.
If the response packets did not contain a valid response
code in the first line of the UDP packet, the Asterisk
SIP channel driver would fail to parse the packet
properly and would cause the Asterisk process to die
with a segmentation fault. This results in all active
calls and other sessions being lost.
Versiones afectadas:
Asterisk Open Source 1.0.x No verificado. Al no ser m谩s mantenido.
Asterisk Open Source 1.2.x All versions prior to 1.2.18
Asterisk Open Source 1.4.x All versions prior to 1.4.3
Asterisk Business Edition A.x.x All versions
Asterisk Business Edition B.x.x All versions up to and including B.1.3.2
AsteriskNOW pre-release All version up to and including Beta5
Asterisk Appliance Developer0.x.x All versions prior to 0.4.0
M谩s informaci贸n
Two stack buffer overflows in SIP channel's T.38 SDP parsing code
Two closely related stack based buffer overflows exist in the SIP/SDP
handler of Asterisk, the vulnerabilities are very similar but exist as
two separate unsafe function calls. The T38FaxRateManagement and
T38FaxUdpEC SDP parameters can be exploited remotely leading to
arbitrary code execution without authentication. In order for these
overflows to occur, t38 fax over SIP must be enabled in sip.conf.
Examples of SIP INVITE packets are shown below, however these
vulnerabilities can be triggered with a number of different SIP messages
affecting calls received by Asterisk, or in response to calls made by
Asterisk.
Versiones afectadas:
Asterisk Open Source 1.0.x No afectada. No soporte T38
Asterisk Open Source 1.2.x No afectada. No soporte T38
Asterisk Open Source 1.4.x All versions prior to 1.4.3
Asterisk Business Edition A.x.x No afectada. No soporte T38
Asterisk Business Edition B.x.x No afectada. No soporte T38
AsteriskNOW pre-release All version up to and including Beta5
Asterisk Appliance Developer0.x.x All versions prior to 0.4.0