---------- Mensagem encaminhada ----------
De: "Asterisk Security Team" <[email protected]>
Data: 28/01/2015 21:31
Assunto: [asterisk-dev] AST-2015-001: File descriptor leak when
incompatible codecs are offered
Para: <[email protected]>
Cc:

               Asterisk Project Security Advisory - AST-2015-001

         Product        Asterisk
         Summary        File descriptor leak when incompatible codecs are
                        offered
    Nature of Advisory  Resource exhaustion
      Susceptibility    Remote Authenticated Sessions
         Severity       Major
      Exploits Known    No
       Reported On      6 January, 2015
       Reported By      Y Ateya
        Posted On       9 January, 2015
     Last Updated On    January 28, 2015
     Advisory Contact   Mark Michelson <mmichelson AT digium DOT com>
         CVE Name       Pending

    Description  Asterisk may be configured to only allow specific audio or
                 video codecs to be used when communicating with a
                 particular endpoint. When an endpoint sends an SDP offer
                 that only lists codecs not allowed by Asterisk, the offer
                 is rejected. However, in this case, RTP ports that are
                 allocated in the process are not reclaimed.

                 This issue only affects the PJSIP channel driver in
                 Asterisk. Users of the chan_sip channel driver are not
                 affected.

                 As the resources are allocated after authentication, this
                 issue only affects communications with authenticated
                 endpoints.

    Resolution  The reported leak has been patched.

                               Affected Versions
                         Product                       Release
                                                       Series
                  Asterisk Open Source                  1.8.x   Unaffected
                  Asterisk Open Source                  11.x    Unaffected
                  Asterisk Open Source                  12.x    All versions
                  Asterisk Open Source                  13.x    All versions
                   Certified Asterisk                  1.8.28   Unaffected
                   Certified Asterisk                   11.6    Unaffected

                                  Corrected In
                            Product                              Release
                      Asterisk Open Source                    12.8.1, 13.1.1

                                    Patches
                                SVN URL
Revision
   http://downloads.asterisk.org/pub/security/AST-2015-001-12.diff
 Asterisk
                                                                     12
   http://downloads.asterisk.org/pub/security/AST-2015-001-13.diff
 Asterisk
                                                                     13

    Links  https://issues.asterisk.org/jira/browse/ASTERISK-24666

    Asterisk Project Security Advisories are posted at
    http://www.asterisk.org/security

    This document may be superseded by later versions; if so, the latest
    version will be posted at
    http://downloads.digium.com/pub/security/AST-2015-001.pdf and
    http://downloads.digium.com/pub/security/AST-2015-001.html

                                Revision History
         Date            Editor                  Revisions Made
    9 January, 2015  Mark Michelson  Initial creation

               Asterisk Project Security Advisory - AST-2015-001
              Copyright (c) 2015 Digium, Inc. All Rights Reserved.
  Permission is hereby granted to distribute and publish this advisory in
its
                           original, unaltered form.


--
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com --

asterisk-dev mailing list
To UNSUBSCRIBE or update options visit:
   http://lists.digium.com/mailman/listinfo/asterisk-dev
_______________________________________________
KHOMP: completa linha de placas externas FXO, FXS, GSM e E1
Media Gateways de 1 a 64 E1s para SIP com R2, ISDN e SS7
Intercomunicadores para acesso remoto via rede IP e telefones IP
Conheça todo o portfólio em www.Khomp.com
_______________________________________________
ALIGERA – Fabricante e desenvolvedor nacional de Soluções para telefonia IP .
Gateway Sip, Placas de 1E1, 2E1, 4E1 e 8E1 para PCI ou PCI Express.
Banco de Canais Analógicos  – Appliance Asterisk Acesse www.aligera.com.br
_______________________________________________
DIGIVOICE: Fabricante pioneiro em Banco de Canais e Placas E1, GSM, FXO e FXS 
para Asterisk e Elastix. Temos Cursos de Telefonia IP e Asterisk.
Construa soluções de PABX IP com produtos DigiVoice - visite  
www.digivoice.com.br
_______________________________________________
Para remover seu email desta lista, basta enviar um email em branco para 
[email protected]

Responder a