Bug#440187: CVE-2007-4521 remote denial of service when using IMAP voicemail storage backend

Nico Golde nion at debian.org
Thu Aug 30 14:10:35 UTC 2007


Package: asterisk
Version: 1:1.4.11~dfsg-1
Severity: important
Tags: security

Hi,
a CVE has been issued against asterisk:
CVE-2007-4521[0]:
Asterisk Open Source 1.4.5 through 1.4.11, when configured 
to use an IMAP voicemail storage backend, allows remote 
attackers to cause a denial of service via an e-mail with an 
"invalid/corrupted" MIME body, which triggers a crash when 
the recipient listens to voicemail.

I can't find anything about this in the changelog so I 
assume the version in unstable is still vulnerable. Please 
include the CVE id into your changelog with the fix.

Kind regards
Nico
-- 
Nico Golde - http://ngolde.de - nion at jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/pkg-voip-maintainers/attachments/20070830/2203363d/attachment.pgp 


More information about the Pkg-voip-maintainers mailing list