Package: asterisk
Version: 1:1.4.11~dfsg-1
Severity: important
Tags: security

Hi,
a CVE has been issued against asterisk:
CVE-2007-4521[0]:
Asterisk Open Source 1.4.5 through 1.4.11, when configured 
to use an IMAP voicemail storage backend, allows remote 
attackers to cause a denial of service via an e-mail with an 
"invalid/corrupted" MIME body, which triggers a crash when 
the recipient listens to voicemail.

I can't find anything about this in the changelog so I 
assume the version in unstable is still vulnerable. Please 
include the CVE id into your changelog with the fix.

Kind regards
Nico
-- 
Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgprjr95x2LfG.pgp
Description: PGP signature

Reply via email to