Bug#364195: CVE-2006-1827: arbitrary code execution

2006-04-21 Thread Stefan Fritsch
Package: asterisk Severity: grave Tags: security Justification: user security hole CVE-2006-1827: Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but trigg

Bug#364195: CVE-2006-1827: arbitrary code execution

2006-04-21 Thread Kilian Krause
Hi Stefan, Am Freitag, den 21.04.2006, 22:24 +0200 schrieb Stefan Fritsch: > Package: asterisk > Severity: grave > Tags: security > Justification: user security hole > > > CVE-2006-1827: > Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and > earlier allows remote attackers to execut