Mandriva Linux Security Advisory : asterisk (MDVSA-2014:078)

high Nessus Plugin ID 73582

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

Multiple vulnerabilities has been discovered and corrected in asterisk :

Sending a HTTP request that is handled by Asterisk with a large number of Cookie headers could overflow the stack. You could even exhaust memory if you sent an unlimited number of headers in the request (CVE-2014-2286).

An attacker can use all available file descriptors using SIP INVITE requests. Asterisk will respond with code 400, 420, or 422 for INVITEs meeting this criteria. Each INVITE meeting these conditions will leak a channel and several file descriptors. The file descriptors cannot be released without restarting Asterisk which may allow intrusion detection systems to be bypassed by sending the requests slowly (CVE-2014-2287).

The updated packages has been upgraded to the 11.8.1 version which is not vulnerable to these issues.

Solution

Update the affected packages.

See Also

http://downloads.asterisk.org/pub/security/AST-2014-001.html

http://downloads.asterisk.org/pub/security/AST-2014-002.html

http://www.nessus.org/u?14c01017

Plugin Details

Severity: High

ID: 73582

File Name: mandriva_MDVSA-2014-078.nasl

Version: 1.11

Type: local

Published: 4/17/2014

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:asterisk, p-cpe:/a:mandriva:linux:asterisk-addons, p-cpe:/a:mandriva:linux:asterisk-devel, p-cpe:/a:mandriva:linux:asterisk-firmware, p-cpe:/a:mandriva:linux:asterisk-gui, p-cpe:/a:mandriva:linux:asterisk-plugins-alsa, p-cpe:/a:mandriva:linux:asterisk-plugins-calendar, p-cpe:/a:mandriva:linux:asterisk-plugins-cel, p-cpe:/a:mandriva:linux:asterisk-plugins-corosync, p-cpe:/a:mandriva:linux:asterisk-plugins-curl, p-cpe:/a:mandriva:linux:asterisk-plugins-dahdi, p-cpe:/a:mandriva:linux:asterisk-plugins-fax, p-cpe:/a:mandriva:linux:asterisk-plugins-festival, p-cpe:/a:mandriva:linux:asterisk-plugins-ices, p-cpe:/a:mandriva:linux:asterisk-plugins-jabber, p-cpe:/a:mandriva:linux:asterisk-plugins-jack, p-cpe:/a:mandriva:linux:asterisk-plugins-ldap, p-cpe:/a:mandriva:linux:asterisk-plugins-lua, p-cpe:/a:mandriva:linux:asterisk-plugins-minivm, p-cpe:/a:mandriva:linux:asterisk-plugins-mobile, p-cpe:/a:mandriva:linux:asterisk-plugins-mp3, p-cpe:/a:mandriva:linux:asterisk-plugins-mysql, p-cpe:/a:mandriva:linux:asterisk-plugins-ooh323, p-cpe:/a:mandriva:linux:asterisk-plugins-osp, p-cpe:/a:mandriva:linux:asterisk-plugins-oss, p-cpe:/a:mandriva:linux:asterisk-plugins-pgsql, p-cpe:/a:mandriva:linux:asterisk-plugins-pktccops, p-cpe:/a:mandriva:linux:asterisk-plugins-portaudio, p-cpe:/a:mandriva:linux:asterisk-plugins-radius, p-cpe:/a:mandriva:linux:asterisk-plugins-saycountpl, p-cpe:/a:mandriva:linux:asterisk-plugins-skinny, p-cpe:/a:mandriva:linux:asterisk-plugins-snmp, p-cpe:/a:mandriva:linux:asterisk-plugins-speex, p-cpe:/a:mandriva:linux:asterisk-plugins-sqlite, p-cpe:/a:mandriva:linux:asterisk-plugins-tds, p-cpe:/a:mandriva:linux:asterisk-plugins-unistim, p-cpe:/a:mandriva:linux:asterisk-plugins-voicemail, p-cpe:/a:mandriva:linux:asterisk-plugins-voicemail-imap, p-cpe:/a:mandriva:linux:asterisk-plugins-voicemail-plain, p-cpe:/a:mandriva:linux:lib64asteriskssl1, cpe:/o:mandriva:business_server:1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 4/16/2014

Reference Information

CVE: CVE-2014-2286, CVE-2014-2287

BID: 66093, 66094

MDVSA: 2014:078