[asterisk-users] AST-2022-003: func_odbc: Possible SQL Injection

2022-04-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2022-003 Product Asterisk Summary func_odbc: Possible SQL Injection Nature of Advisory SQL injection

[asterisk-users] AST-2022-002: res_stir_shaken: SSRF vulnerability with Identity header

2022-04-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2022-002 ProductAsterisk Summaryres_stir_shaken: SSRF vulnerability with Identity header

[asterisk-users] AST-2022-001: res_stir_shaken: resource exhaustion with large files

2022-04-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2022-001 ProductAsterisk Summaryres_stir_shaken: resource exhaustion with large files

[asterisk-users] AST-2022-006: pjproject: unconstrained malformed multipart SIP message

2022-03-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2022-006 ProductAsterisk Summarypjproject: unconstrained malformed multipart SIP message

[asterisk-users] AST-2022-005: pjproject: undefined behavior after freeing a dialog set

2022-03-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2022-005 ProductAsterisk Summarypjproject: undefined behavior after freeing a dialog set

[asterisk-users] AST-2022-004: pjproject: integer underflow on STUN message

2022-03-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2022-004 ProductAsterisk Summarypjproject: possible integer underflow on STUN message

[asterisk-users] AST-2021-009: pjproject/pjsip: crash when SSL socket destroyed during handshake

2021-07-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-009 ProductAsterisk Summarypjproject/pjsip: crash when SSL socket destroyed during handshake

[asterisk-users] AST-2021-008: Remote crash when using IAX2 channel driver

2021-07-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-008 Product Asterisk Summary Remote crash when using IAX2 channel driver Nature of Advisory Denial of service

[asterisk-users] AST-2021-007: Remote Crash Vulnerability in PJSIP channel driver

2021-07-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-007 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP channel driver Nature of Advisory Denial of Service

[asterisk-users] AST-2021-006: Crash when negotiating T.38 with a zero port

2021-03-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-006 ProductAsterisk SummaryCrash when negotiating T.38 with a zero port Nature of Advisory Remote Crash

[asterisk-users] AST-2021-005: Remote Crash Vulnerability in PJSIP channel driver

2021-02-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-005 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP channel driver Nature of Advisory Denial of Service

[asterisk-users] AST-2021-004: An unsuspecting user could crash Asterisk with multiple hold/unhold requests

2021-02-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-004 ProductAsterisk SummaryAn unsuspecting user could crash Asterisk with multiple hold/unhold requests

[asterisk-users] AST-2021-003: Remote attacker could prematurely tear down SRTP calls

2021-02-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-003 ProductAsterisk SummaryRemote attacker could prematurely tear down SRTP calls

[asterisk-users] AST-2021-002: Remote crash possible when negotiating T.38

2021-02-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-002 Product Asterisk Summary Remote crash possible when negotiating T.38 Nature of Advisory Denial of service

[asterisk-users] AST-2021-001: Remote crash in res_pjsip_diversion

2021-02-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2021-001 Product Asterisk Summary Remote crash in res_pjsip_diversion Nature of Advisory Denial of service

[asterisk-users] AST-2020-004: Remote crash in res_pjsip_diversion

2020-12-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2020-004 Product Asterisk Summary Remote crash in res_pjsip_diversion Nature of Advisory Denial of service

[asterisk-users] AST-2020-003: Remote crash in res_pjsip_diversion

2020-12-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2020-003 Product Asterisk Summary Remote crash in res_pjsip_diversion Nature of Advisory Denial of service

[asterisk-users] AST-2020-002: Outbound INVITE loop on challenge with different nonce.

2020-11-05 Thread Asterisk Security Team
Asterisk Project Security Advisory – AST-2020-002 ProductAsterisk SummaryOutbound INVITE loop on challenge with different nonce.

[asterisk-users] AST-2020-001: Remote crash in res_pjsip_session

2020-11-05 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2020-001 Product Asterisk Summary Remote crash in res_pjsip_session Nature of Advisory Denial of service

[asterisk-users] AST-2019-008: Re-invite with T.38 and malformed SDP causes crash.

2019-11-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - ProductAsterisk SummaryRe-invite with T.38 and malformed SDP causes crash. Nature of Advisory Remote Crash

[asterisk-users] AST-2019-007: AMI user could execute system commands.

2019-11-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-007 ProductAsterisk SummaryAMI user could execute system commands. Nature of Advisory Remote Code Execution

[asterisk-users] AST-2019-006: SIP request can change address of a SIP peer.

2019-11-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-006 ProductAsterisk SummarySIP request can change address of a SIP peer. Nature of Advisory Denial of Service

[asterisk-users] AST-2019-005: Remote Crash Vulnerability in audio transcoding

2019-09-05 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-005 Product Asterisk Summary Remote Crash Vulnerability in audio transcoding Nature of Advisory Denial of Service

[asterisk-users] AST-2019-004: Crash when negotiating for T.38 with a declined stream

2019-09-05 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-004 ProductAsterisk SummaryCrash when negotiating for T.38 with a declined stream

[asterisk-users] AST-2019-003: Remote Crash Vulnerability in chan_sip channel driver

2019-07-11 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-003 ProductAsterisk SummaryRemote Crash Vulnerability in chan_sip channel driver

[asterisk-users] AST-2019-002: Remote crash vulnerability with MESSAGE messages

2019-07-11 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-002 Product Asterisk Summary Remote crash vulnerability with MESSAGE messages Nature of Advisory Denial Of Service

[asterisk-users] AST-2019-001: Remote crash vulnerability with SDP protocol violation

2019-02-28 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2019-001 ProductAsterisk SummaryRemote crash vulnerability with SDP protocol violation

[asterisk-users] AST-2018-010: Remote crash vulnerability DNS SRV and NAPTR lookups

2018-11-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-010 ProductAsterisk SummaryRemote crash vulnerability DNS SRV and NAPTR lookups Nature of Advisory Denial Of Service

[asterisk-users] AST-2018-010:

2018-11-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-010 ProductAsterisk Remote crash vulnerability DNS SRV and NAPTR lookups Nature of Advisory Denial Of Service

[asterisk-users] AST-2018-009: Remote crash vulnerability in HTTP websocket upgrade

2018-09-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-009 ProductAsterisk SummaryRemote crash vulnerability in HTTP websocket upgrade Nature of Advisory Denial Of Service

[asterisk-users] AST-2018-008: PJSIP endpoint presence disclosure when using ACL

2018-06-11 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-008 ProductAsterisk SummaryPJSIP endpoint presence disclosure when using ACL Nature of Advisory Unauthorized data disclosure

[asterisk-users] AST-2018-007: Infinite loop when reading iostreams

2018-06-11 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-007 ProductAsterisk SummaryInfinite loop when reading iostreams Nature of Advisory Denial of Service

[asterisk-users] AST-2018-006: WebSocket frames with 0 sized payload causes DoS

2018-02-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-006 ProductAsterisk SummaryWebSocket frames with 0 sized payload causes DoS Nature of Advisory Denial of Service

[asterisk-users] AST-2018-005: Crash when large numbers of TCP connections are closed suddenly

2018-02-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-005 ProductAsterisk SummaryCrash when large numbers of TCP connections are closed suddenly

[asterisk-users] AST-2018-004: Crash when receiving SUBSCRIBE request

2018-02-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-004 Product Asterisk Summary Crash when receiving SUBSCRIBE request Nature of Advisory Remote Crash

[asterisk-users] AST-2018-003: Crash with an invalid SDP fmtp attribute

2018-02-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-003 ProductAsterisk SummaryCrash with an invalid SDP fmtp attribute Nature of Advisory Remote crash

[asterisk-users] AST-2018-002: Crash when given an invalid SDP media format description

2018-02-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-002 ProductAsterisk SummaryCrash when given an invalid SDP media format description

[asterisk-users] AST-2018-001: Crash when receiving unnegotiated dynamic payload

2018-02-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2018-001 Product Asterisk Summary Crash when receiving unnegotiated dynamic payload Nature of Advisory Remote Crash

[asterisk-users] AST-2017-014: Crash in PJSIP resource when missing a contact header

2017-12-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-014 ProductAsterisk SummaryCrash in PJSIP resource when missing a contact header

[asterisk-users] AST-2017-012: Remote Crash Vulnerability in RTCP Stack

2017-12-13 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-012 Product Asterisk Summary Remote Crash Vulnerability in RTCP Stack Nature of Advisory Denial of Service

[asterisk-users] AST-2017-013: DOS Vulnerability in Asterisk chan_skinny

2017-12-01 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-013 Product Asterisk Summary DOS Vulnerability in Asterisk chan_skinny Nature of Advisory Denial of Service

[asterisk-users] :

2017-12-01 Thread Asterisk Security Team
The Asterisk Development Team has announced security releases for Certified Asterisk 13.13 and Asterisk 13, 14 and 15. The available security releases are released as versions 13.13-cert8, 13.18.3, 14.7.3 and 15.1.3. These releases are available for immediate download at

[asterisk-users] AST-2017-011: Memory leak in pjsip session resource

2017-11-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-011 ProductAsterisk SummaryMemory leak in pjsip session resource Nature of Advisory Memory leak

[asterisk-users] AST-2017-010: Buffer overflow in CDR's set user

2017-11-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-010 ProductAsterisk SummaryBuffer overflow in CDR's set user Nature of Advisory Buffer Overflow

[asterisk-users] AST-2017-009: Buffer overflow in pjproject header parsing can cause crash in Asterisk

2017-11-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-009 ProductAsterisk SummaryBuffer overflow in pjproject header parsing can cause crash in Asterisk

[asterisk-users] AST-2017-008: RTP/RTCP information leak

2017-09-19 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-008 ProductAsterisk SummaryRTP/RTCP information leak Nature of Advisory Unauthorized data disclosure

[asterisk-users] AST-2017-007: Remote Crash Vulerability in res_pjsip

2017-08-31 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-007 ProductAsterisk SummaryRemote Crash Vulerability in res_pjsip Nature of Advisory Denial of Service

[asterisk-users] AST-2017-005: Media takeover in RTP stack

2017-08-31 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-005 ProductAsterisk SummaryMedia takeover in RTP stack Nature of Advisory Unauthorized data disclosure

[asterisk-users] AST-2017-006: Shell access command injection in app_minivm

2017-08-31 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-006 ProductAsterisk SummaryShell access command injection in app_minivm Nature of Advisory Unauthorized command execution

[asterisk-users] AST-2017-004: Memory exhaustion on short SCCP packets

2017-05-19 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-004 Product Asterisk Summary Memory exhaustion on short SCCP packets Nature of Advisory Denial of Service

[asterisk-users] AST-2017-002: Buffer Overrun in PJSIP transaction layer

2017-05-19 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-002 ProductAsterisk SummaryBuffer Overrun in PJSIP transaction layer Nature of Advisory Buffer Overrun/Crash

[asterisk-users] AST-2017-003: Crash in PJSIP multi-part body parser

2017-05-19 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-003 ProductAsterisk SummaryCrash in PJSIP multi-part body parser Nature of Advisory Remote Crash

[asterisk-users] AST-2017-001: Buffer overflow in CDR's set user

2017-04-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2017-001 ProductAsterisk SummaryBuffer overflow in CDR's set user Nature of Advisory Buffer Overflow

[asterisk-users] AST-2016-009:

2016-12-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - ASTERISK-2016-009 ProductAsterisk Summary Nature of Advisory Authentication Bypass SusceptibilityRemote unauthenticated

[asterisk-users] AST-2016-008: Crash on SDP offer or answer from endpoint using Opus

2016-12-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-008 ProductAsterisk SummaryCrash on SDP offer or answer from endpoint using Opus

[asterisk-users] AST-2016-007: UPDATE

2016-10-25 Thread Asterisk Security Team
On September 8, the Asterisk development team released the AST-2016-007 security advisory. The security advisory involved an RTP resource exhaustion that could be targeted due to a flaw in the "allowoverlap" option of chan_sip. Due to new information presented to us by Walter Doekes, we have made

[asterisk-users] AST-2016-007: RTP Resource Exhaustion

2016-09-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-007 ProductAsterisk SummaryRTP Resource Exhaustion Nature of Advisory Denial of Service

[asterisk-users] AST-2016-006: Crash on ACK from unknown endpoint

2016-09-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-006 ProductAsterisk SummaryCrash on ACK from unknown endpoint Nature of Advisory Remote Crash

[asterisk-users] AST-2016-005: TCP denial of service in PJProject

2016-04-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-005 ProductAsterisk SummaryTCP denial of service in PJProject Nature of Advisory Crash/Denial of Service

[asterisk-users] AST-2016-004: Long Contact URIs in REGISTER requests can crash Asterisk

2016-04-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-004 ProductAsterisk SummaryLong Contact URIs in REGISTER requests can crash Asterisk

[asterisk-users] AST-2016-003: Remote crash vulnerability when receiving UDPTL FAX data.

2016-02-03 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-003 ProductAsterisk SummaryRemote crash vulnerability when receiving UDPTL FAX data.

[asterisk-users] AST-2016-001: BEAST vulnerability in HTTP server

2016-02-03 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-001 ProductAsterisk SummaryBEAST vulnerability in HTTP server Nature of Advisory Unauthorized data disclosure due to

[asterisk-users] AST-2016-002: File descriptor exhaustion in chan_sip

2016-02-03 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2016-002 ProductAsterisk SummaryFile descriptor exhaustion in chan_sip Nature of Advisory Denial of Service

[asterisk-users] AST-2015-003: TLS Certificate Common name NULL byte exploit

2015-04-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2015-003 ProductAsterisk SummaryTLS Certificate Common name NULL byte exploit Nature of Advisory Man in the Middle Attack

[asterisk-users] AST-2015-001: File descriptor leak when incompatible codecs are offered

2015-01-28 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2015-001 ProductAsterisk SummaryFile descriptor leak when incompatible codecs are offered

[asterisk-users] AST-2015-002: Mitigation for libcURL HTTP request injection vulnerability

2015-01-28 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2015-002 ProductAsterisk SummaryMitigation for libcURL HTTP request injection vulnerability

[asterisk-users] AST-2014-019: Remote Crash Vulnerability in WebSocket Server

2014-12-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-019 ProductAsterisk SummaryRemote Crash Vulnerability in WebSocket Server Nature of Advisory Denial of Service

[asterisk-users] AST-2014-012: Mixed IP address families in access control lists may permit unwanted traffic.

2014-11-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-012 ProductAsterisk SummaryMixed IP address families in access control lists may permit unwanted traffic.

[asterisk-users] AST-2014-014: High call load may result in hung channels in ConfBridge.

2014-11-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-014 ProductAsterisk SummaryHigh call load may result in hung channels in ConfBridge.

[asterisk-users] AST-2014-013: PJSIP ACLs are not loaded on startup

2014-11-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-013 ProductAsterisk SummaryPJSIP ACLs are not loaded on startup Nature of Advisory Unauthorized Access

[asterisk-users] AST-2014-015: Remote Crash Vulnerability in PJSIP channel driver

2014-11-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-015 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP channel driver Nature of Advisory Denial of Service

[asterisk-users] AST-2014-016: Remote Crash Vulnerability in PJSIP channel driver

2014-11-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-016 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP channel driver Nature of Advisory Denial of Service

[asterisk-users] AST-2014-017: font size=3 style=font-size: 12ptPermission escalation through ConfBridge actions/dialplan functions/font

2014-11-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-017 ProductAsterisk SummaryPermission escalation through ConfBridge actions/dialplan functions

[asterisk-users] AST-2014-018: AMI permission escalation through DB dialplan function

2014-11-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-018 ProductAsterisk SummaryAMI permission escalation through DB dialplan function

[asterisk-users] AST-2014-011: Asterisk Susceptibility to POODLE Vulnerability

2014-10-20 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-011 ProductAsterisk SummaryAsterisk Susceptibility to POODLE Vulnerability Nature of Advisory Unauthorized Data Disclosure

[asterisk-users] AST-2014-009: Remote crash based on malformed SIP subscription requests

2014-09-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-009 ProductAsterisk SummaryRemote crash based on malformed SIP subscription requests

[asterisk-users] AST-2014-010: Remote crash when handling out of call message in certain dialplan configurations

2014-09-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-010 ProductAsterisk SummaryRemote crash when handling out of call message in certain dialplan configurations

[asterisk-users] AST-2014-005: Remote Crash in PJSIP Channel Driver's Publish/Subscribe Framework

2014-06-12 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-005 ProductAsterisk SummaryRemote Crash in PJSIP Channel Driver's Publish/Subscribe Framework

[asterisk-users] AST-2014-006: Asterisk Manager User Unauthorized Shell Access

2014-06-12 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-006 Product Asterisk Summary Asterisk Manager User Unauthorized Shell Access Nature of Advisory Permission Escalation

[asterisk-users] AST-2014-008: Denial of Service in PJSIP Channel Driver Subscriptions

2014-06-12 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-008 ProductAsterisk SummaryDenial of Service in PJSIP Channel Driver Subscriptions

[asterisk-users] AST-2014-007: Exhaustion of Allowed Concurrent HTTP Connections

2014-06-12 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-007 Product Asterisk Summary Exhaustion of Allowed Concurrent HTTP Connections Nature of Advisory Denial Of Service

[asterisk-users] AST-2014-002: Denial of Service Through File Descriptor Exhaustion with chan_sip Session-Timers

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-002 ProductAsterisk SummaryDenial of Service Through File Descriptor Exhaustion with chan_sip Session-Timers

[asterisk-users] AST-2014-001: Stack Overflow in HTTP Processing of Cookie Headers.

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-001 ProductAsterisk SummaryStack Overflow in HTTP Processing of Cookie Headers. Nature of Advisory Denial Of Service

[asterisk-users] AST-2014-003: Remote Crash Vulnerability in PJSIP channel driver

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-003 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP channel driver Nature of Advisory Denial of Service

[asterisk-users] AST-2014-004: Remote Crash Vulnerability in PJSIP Channel Driver Subscription Handling

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-004 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP Channel Driver Subscription Handling

[asterisk-users] AST-2013-006: Buffer Overflow when receiving odd length 16 bit SMS message

2013-12-16 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-006 ProductAsterisk SummaryBuffer Overflow when receiving odd length 16 bit SMS message

[asterisk-users] AST-2013-007: Asterisk Manager User Dialplan Permission Escalation

2013-12-16 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-007 ProductAsterisk SummaryAsterisk Manager User Dialplan Permission Escalation Nature of Advisory Permission Escalation

[asterisk-users] AST-2013-004: Remote Crash From Late Arriving SIP ACK With SDP

2013-08-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-004 Product Asterisk Summary Remote Crash From Late Arriving SIP ACK With SDP Nature of Advisory Remote Crash

[asterisk-users] AST-2013-005: Remote Crash when Invalid SDP is sent in SIP Request

2013-08-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-005 ProductAsterisk SummaryRemote Crash when Invalid SDP is sent in SIP Request Nature of Advisory Remote Crash

[asterisk-users] AST-2013-001: Buffer Overflow Exploit Through SIP SDP Header

2013-03-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-001 Product Asterisk Summary Buffer Overflow Exploit Through SIP SDP Header Nature of Advisory Exploitable Stack Buffer Overflow

[asterisk-users] AST-2013-002: Denial of Service in HTTP server

2013-03-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-002 Product Asterisk Summary Denial of Service in HTTP server Nature of Advisory Denial of Service

[asterisk-users] AST-2013-003: Username disclosure in SIP channel driver

2013-03-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-003 Product Asterisk Summary Username disclosure in SIP channel driver Nature of Advisory Unauthorized data disclosure

[asterisk-users] AST-2012-014: Crashes due to large stack allocations when using TCP

2013-01-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-014 ProductAsterisk SummaryCrashes due to large stack allocations when using TCP

[asterisk-users] AST-2012-015: Denial of Service Through Exploitation of Device State Caching

2013-01-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-015 ProductAsterisk SummaryDenial of Service Through Exploitation of Device State Caching

[asterisk-users] AST-2012-012: Asterisk Manager User Unauthorized Shell Access

2012-08-30 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-012 Product Asterisk Summary Asterisk Manager User Unauthorized Shell Access Nature of Advisory Permission Escalation

[asterisk-users] AST-2012-013: ACL rules ignored when placing outbound calls by certain IAX2 users

2012-08-30 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-013 ProductAsterisk SummaryACL rules ignored when placing outbound calls by certain IAX2 users

[asterisk-users] AST-2012-009: Skinny Channel Driver Remote Crash Vulnerability

2012-06-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-009 Product Asterisk Summary Skinny Channel Driver Remote Crash Vulnerability Nature of Advisory Denial of Service

[asterisk-users] AST-2012-007: Remote crash vulnerability in IAX2 channel driver.

2012-05-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-007 ProductAsterisk SummaryRemote crash vulnerability in IAX2 channel driver. Nature of Advisory Remote crash

[asterisk-users] AST-2012-008: Skinny Channel Driver Remote Crash Vulnerability

2012-05-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-008 Product Asterisk Summary Skinny Channel Driver Remote Crash Vulnerability Nature of Advisory Denial of Service

[asterisk-users] AST-2012-004: Asterisk Manager User Unauthorized Shell Access

2012-04-23 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-004 Product Asterisk Summary Asterisk Manager User Unauthorized Shell Access Nature of Advisory Permission Escalation

  1   2   >