Debian Security Advisory
DSA-2605-2 asterisk -- several issues
- Date Reported:
- 19 Jan 2013
- Affected Packages:
- asterisk
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 697230, Bug 698112, Bug 698118.
In Mitre's CVE dictionary: CVE-2012-5976, CVE-2012-5977. - More information:
-
Several vulnerabilities were discovered in Asterisk, a PBX and telephony toolkit, that allow remote attackers to perform denial of service attacks.
For the stable distribution (squeeze), these problems have been fixed in version 1:1.6.2.9-2+squeeze10.
For the testing distribution (wheezy) and unstable distribution (sid), these problems will be fixed soon.
We recommend that you upgrade your asterisk packages.