CVE-2009-4055

Priority
Medium
Description
rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1,
1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition
B.x.x before B.2.5.13, C.2.x.x before C.2.4.6, and C.3.x.x before C.3.2.3;
and s800i 1.3.x before 1.3.0.6 allows remote attackers to cause a denial of
service (daemon crash) via an RTP comfort noise payload with a long data
length.
References
Bugs
Package
Upstream:released (1:1.6.2.0~rc7-1)
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected (1:1.6.2.2-1ubuntu2)
Ubuntu 11.04 (Natty Narwhal):not-affected (1:1.6.2.2-1ubuntu2)
Ubuntu 11.10 (Oneiric Ocelot):not-affected (1:1.6.2.2-1ubuntu2)
Patches:
Upstream:http://downloads.asterisk.org/pub/security/AST-2009-010-1.4.diff.txt
Debdiff:https://bugs.launchpad.net/ubuntu/karmic/+source/asterisk/+bug/491632
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:20:24 UTC (commit 5347)