Advisories ยป MGASA-2015-0010

Updated asterisk packages fix CVE-2014-9374

Publication date: 07 Jan 2015
Modification date: 07 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9374

Description

Updated asterisk packages fix security vulnerability:

Double free vulnerability in the WebSocket Server (res_http_websocket module)
in Asterisk Open Source 11.x before 11.14.2 allows remote attackers to cause a
denial of service (crash) by sending a zero length frame after a non-zero
length frame (CVE-2014-9374).
                

References

SRPMS

4/core