Updated asterisk packages fix CVE-2014-9374
Publication date: 07 Jan 2015Modification date: 07 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9374
Description
Updated asterisk packages fix security vulnerability: Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2 allows remote attackers to cause a denial of service (crash) by sending a zero length frame after a non-zero length frame (CVE-2014-9374).
References
- https://bugs.mageia.org/show_bug.cgi?id=14915
- http://downloads.asterisk.org/pub/security/AST-2014-019.html
- http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-11.14.2
- http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-11.14.2-summary.html
- http://www.gentoo.org/security/en/glsa/glsa-201412-51.xml
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9374
SRPMS
4/core
- asterisk-11.14.2-1.mga4