Hide Forgot
AST-2011-004 [1] describes a remote crash vulnerability in the Asterisk TCP/TLS server. If a remote, unauthenticated, attacker were to rapidly open and close TCP connections to services using the ast_tcptls_* API, they could cause Asterisk to crash after dereferencing a NULL pointer. This flaw affects 1.6.2.x and 1.8.x, and is corrected in 1.6.2.17.1 and 1.8.3.1. [1] http://downloads.asterisk.org/pub/security/AST-2011-004.pdf
This is assigned CVE-2011-1175.
This is corrected via these builds that have the fixes from upstream: Fedora-13: asterisk-1.6.2.18-1.fc13 Fedora-14: asterisk-1.6.2.18-1.fc14 Fedora-15: asterisk-1.8.3.3-1.fc15 Fedora-Rawhide: asterisk-1.8.3.3-1.fc16 EPEL-6: asterisk-1.8.3.3-1.el6