Updated asterisk packages fix security vulnerabilities
Publication date: 26 Jul 2014Modification date: 26 Jul 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-4046 , CVE-2014-4047
Description
Updated asterisk packages fix security vulnerabilities: Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell commands via a MixMonitor action (CVE-2014-4046). Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote attackers to cause a denial of service (connection consumption) via a large number of (1) inactive or (2) incomplete HTTP connections (CVE-2014-4047).
References
- http://downloads.asterisk.org/pub/security/AST-2014-006.html
- http://downloads.asterisk.org/pub/security/AST-2014-007.html
- http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-11.11.0-summary.html
- http://www.mandriva.com/en/support/security/advisories/mbs1/MDVSA-2014:138/
- https://bugs.mageia.org/show_bug.cgi?id=13604
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4046
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4047
SRPMS
3/core
- asterisk-11.11.0-1.mga3
4/core
- asterisk-11.11.0-1.mga4