Candidate: CVE-2014-6610 PublicDate: 2014-11-26 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6610 http://downloads.asterisk.org/pub/security/AST-2014-010.html Description: Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=762164 Priority: medium Discovered-by: Philippe Lindheimer Assigned-to: CVSS: Patches_asterisk: upstream: http://downloads.asterisk.org/pub/security/AST-2014-010-11.diff upstream_asterisk: released (11.12.1, 12.5.1) lucid_asterisk: ignored (reached end-of-life) precise_asterisk: ignored (reached end-of-life) precise/esm_asterisk: DNE (precise was needed) trusty_asterisk: ignored (reached end-of-life) trusty/esm_asterisk: DNE (trusty was needed) utopic_asterisk: ignored (reached end-of-life) vivid_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) vivid/stable-phone-overlay_asterisk: DNE vivid/ubuntu-core_asterisk: DNE wily_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) xenial_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) yakkety_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) zesty_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) artful_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) bionic_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) cosmic_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) disco_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1) devel_asterisk: not-affected (1:13.0.0~dfsg-2ubuntu1)