Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3812

Overview

Vulnerability Score 4.0 4.0
CVE Id CVE-2012-3812
Last Modified 18 Apr 2013 11:24:11
Published 09 Jul 2012 06:55:01
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2012-3812

Summary

Double free vulnerability in apps/app_voicemail.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x before 10.5.2, Certified Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones before 10.5.2-digiumphones allows remote authenticated users to cause a denial of service (daemon crash) by establishing multiple voicemail sessions and accessing both the Urgent mailbox and the INBOX mailbox.

Vulnerable Systems

Application

  • Digium Asterisk 1.8.0

  • Digium Asterisk 1.8.1

  • Digium Asterisk 1.8.1.1

  • Digium Asterisk 1.8.1.2

  • Digium Asterisk 1.8.11.0

  • Digium Asterisk 1.8.11.1

  • Digium Asterisk 1.8.13.0

  • Digium Asterisk 1.8.2

  • Digium Asterisk 1.8.2.1

  • Digium Asterisk 1.8.2.2

  • Digium Asterisk 1.8.2.3

  • Digium Asterisk 1.8.2.4

  • Digium Asterisk 1.8.3

  • Digium Asterisk 1.8.3.1

  • Digium Asterisk 1.8.3.2

  • Digium Asterisk 1.8.3.3

  • Digium Asterisk 1.8.4

  • Digium Asterisk 1.8.4.1

  • Digium Asterisk 1.8.4.2

  • Digium Asterisk 1.8.4.3

  • Digium Asterisk 1.8.4.4

  • Digium Asterisk 1.8.5

  • Digium Asterisk 1.8.5.0

  • Digium Asterisk 1.8.6.0

  • Digium Asterisk 1.8.7.0

  • Digium Asterisk 1.8.7.1

  • Digium Asterisk 1.8.8.0

  • Digium Asterisk 1.8.8.1

  • Digium Asterisk 1.8.8.2

  • Digium Asterisk 1.8.9.0

  • Digium Asterisk 1.8.9.2

  • Digium Asterisk 1.8.9.3

  • Digium Asterisk 10.0.0

  • Digium Asterisk 10.0.1

  • Digium Asterisk 10.1.0

  • Digium Asterisk 10.1.1

  • Digium Asterisk 10.1.2

  • Digium Asterisk 10.1.3

  • Digium Asterisk 10.2.0

  • Digium Asterisk 10.2.1

  • Digium Asterisk 10.3.0

  • Digium Asterisk 10.3.1

  • Digium Asterisk 10.4.0

  • Digium Asterisk 10.4.1

  • Digium Asterisk 10.4.2

  • Digium Asterisk 10.5.0

  • Digium Asterisk 10.5.1

  • Digium Asteriske 1.8.8.0

  • Digium Asteriske 1.8.9.1

  • Digium Certified Asterisk 1.8.11


References

CONFIRM - https://issues.asterisk.org/jira/browse/ASTERISK-20052

CONFIRM - http://downloads.asterisk.org/pub/security/AST-2012-011.html

DEBIAN - DSA-2550

BID - 54317

SECUNIA - 50756

SECUNIA - 50687


Last Updated: 27 May 2016 10:54:50