CVE-2012-1183

Priority
Medium
Description
Stack-based buffer overflow in the milliwatt_generate function in the
Miliwatt application in Asterisk 1.4.x before 1.4.44, 1.6.x before
1.6.2.23, 1.8.x before 1.8.10.1, and 10.x before 10.2.1, when the o option
is used and the internal_timing option is off, allows remote attackers to
cause a denial of service (application crash) via a large number of samples
in an audio packet.
References
Bugs
Package
Upstream:released (1:1.8.10.0~dfsg-1)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):not-affected (1:1.8.10.1~dfsg-1ubuntu1)
Ubuntu 12.10 (Quantal Quetzal):not-affected
Ubuntu 13.04 (Raring Ringtail):not-affected
Ubuntu 13.10 (Saucy Salamander):not-affected
Ubuntu 14.04 LTS (Trusty Tahr):not-affected
Patches:
Upstream:http://downloads.asterisk.org/pub/security/AST-2012-002-1.8.diff
More Information

Valid XHTML 1.0 Strict

Updated: 2013-12-20 21:17:04 UTC (commit 7585)