FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-2947

This CVE name corresponds to:

Entered Topic
2012-05-29 asterisk -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-2947
Phase Assigned(20120529)

Description

chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows remote attackers to cause a denial of service (daemon crash) by placing a call on hold.

References

Source Reference
BUGTRAQ 20120529 AST-2012-007: Remote crash vulnerability in IAX2 channel driver.
CONFIRM http://downloads.asterisk.org/pub/security/AST-2012-007.html
DEBIAN DSA-2493
SECTRACK 1027102
SECUNIA 49303