Summary
The remote host is missing an update to asterisk
announced via advisory DSA 1563-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201563-1
Insight
Joel R. Voss discovered that the IAX2 module of Asterisk, a free software PBX and telephony toolkit performs insufficient validation of IAX2 protocol messages, which may lead to denial of service.
For the stable distribution (etch), this problem has been fixed in version 1.2.13~dfsg-2etch4.
For the unstable distribution (sid), this problem has been fixed in version 1.4.19.1~dfsg-1.
We recommend that you upgrade your asterisk packages.
Severity
Classification
-
CVE CVE-2008-1897 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities