漏洞信息详情
Asterisk format_jpeg.c 整数溢出漏洞
- CNNVD编号:CNNVD-200604-281
- 危害等级: 低危
- CVE编号: CVE-2006-1827
- 漏洞类型: 缓冲区溢出
- 发布时间: 2006-04-18
- 威胁类型: 远程
- 更新时间: 2006-08-23
- 厂 商: digium
- 漏洞来源: Discovery is credi...
漏洞简介
Asterisk 1.2.6及早期版本的format_jpeg.c存在整数符号类型错误。这使得远程攻击者可以借助于一长度值执行任意代码,该长度值传递一长度检验作为负数并且当作为无符号长度时触发缓冲区溢出。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Asterisk Asterisk 0.1.7
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.1.8
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.1.9
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.1.9 -1
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.2
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.3
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.4
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.7 .0
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.7.1
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.7.2
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 0.9 .0
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Asterisk Asterisk 1.0.7
Asterisk asterisk-1.2.7-patch.gz
http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
Debian asterisk-config_1.0.7.dfsg.1-2sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-confi g_1.0.7.dfsg.1-2sarge2_all.deb
Debian asterisk-dev_1.0.7.dfsg.1-2sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-dev_1 .0.7.dfsg.1-2sarge2_all.deb
Debian asterisk-doc_1.0.7.dfsg.1-2sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-doc_1 .0.7.dfsg.1-2sarge2_all.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_alpha.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_amd64.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_arm.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_hppa.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_i386.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_ia64.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_m68k.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_mips.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/asterisk/asterisk-gtk-c onsole_1.0.7.dfsg.1-2sarge2_mipsel.deb
Debian asterisk-gtk-console_1.0.7.dfsg.1-2sarge2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debi
参考网址
来源: MISC
链接:http://www.cipher.org.uk/index.php?p=advisories/Asterisk_Codec_Integer_Overflow_07-04-2006.advisory
来源: ftp.digium.com
链接:http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz
来源: BID
名称: 17561
链接:http://www.securityfocus.com/bid/17561
来源: SUSE
名称: SUSE-SR:2006:009
链接:http://www.novell.com/linux/security/advisories/2006_04_28.HTML
来源: VUPEN
名称: ADV-2006-1478
链接:http://www.frsirt.com/english/advisories/2006/1478
来源: DEBIAN
名称: DSA-1048
链接:http://www.debian.org/security/2006/dsa-1048
来源: SECUNIA
名称: 19897
链接:http://secunia.com/advisories/19897
来源: SECUNIA
名称: 19872
链接:http://secunia.com/advisories/19872
来源: SECUNIA
名称: 19800
链接:http://secunia.com/advisories/19800
受影响实体
- Digium Asterisk:0.1.0
- Digium Asterisk:0.1.1
- Digium Asterisk:0.1.10
- Digium Asterisk:0.1.11
- Digium Asterisk:0.1.12
补丁
暂无
评论