[Full-disclosure] AST-2014-004: Remote Crash Vulnerability in PJSIP Channel Driver Subscription Handling

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-004 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP Channel Driver Subscription Handling

[Full-disclosure] AST-2014-002: Denial of Service Through File Descriptor Exhaustion with chan_sip Session-Timers

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-002 ProductAsterisk SummaryDenial of Service Through File Descriptor Exhaustion with chan_sip Session-Timers

[Full-disclosure] AST-2014-003: Remote Crash Vulnerability in PJSIP channel driver

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-003 ProductAsterisk SummaryRemote Crash Vulnerability in PJSIP channel driver Nature of Advisory Denial of Service

[Full-disclosure] AST-2014-001: Stack Overflow in HTTP Processing of Cookie Headers.

2014-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2014-001 ProductAsterisk SummaryStack Overflow in HTTP Processing of Cookie Headers. Nature of Advisory Denial Of Service

[Full-disclosure] AST-2013-007: Asterisk Manager User Dialplan Permission Escalation

2013-12-16 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-007 ProductAsterisk SummaryAsterisk Manager User Dialplan Permission Escalation Nature of Advisory Permission Escalation

[Full-disclosure] AST-2013-006: Buffer Overflow when receiving odd length 16 bit SMS message

2013-12-16 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-006 ProductAsterisk SummaryBuffer Overflow when receiving odd length 16 bit SMS message

[Full-disclosure] AST-2013-005: Remote Crash when Invalid SDP is sent in SIP Request

2013-08-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-005 ProductAsterisk SummaryRemote Crash when Invalid SDP is sent in SIP Request Nature of Advisory Remote Crash

[Full-disclosure] AST-2013-004: Remote Crash From Late Arriving SIP ACK With SDP

2013-08-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-004 Product Asterisk Summary Remote Crash From Late Arriving SIP ACK With SDP Nature of Advisory Remote Crash

[Full-disclosure] AST-2013-003: Username disclosure in SIP channel driver

2013-03-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-003 Product Asterisk Summary Username disclosure in SIP channel driver Nature of Advisory Unauthorized data disclosure

[Full-disclosure] AST-2013-002: Denial of Service in HTTP server

2013-03-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-002 Product Asterisk Summary Denial of Service in HTTP server Nature of Advisory Denial of Service

[Full-disclosure] AST-2013-001: Buffer Overflow Exploit Through SIP SDP Header

2013-03-27 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-001 Product Asterisk Summary Buffer Overflow Exploit Through SIP SDP Header Nature of Advisory Exploitable Stack Buffer Overflow

[Full-disclosure] AST-2012-015: Denial of Service Through Exploitation of Device State Caching

2013-01-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-015 ProductAsterisk SummaryDenial of Service Through Exploitation of Device State Caching

[Full-disclosure] AST-2012-014: Crashes due to large stack allocations when using TCP

2013-01-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-014 ProductAsterisk SummaryCrashes due to large stack allocations when using TCP

[Full-disclosure] AST-2012-013: ACL rules ignored when placing outbound calls by certain IAX2 users

2012-08-30 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-013 ProductAsterisk SummaryACL rules ignored when placing outbound calls by certain IAX2 users

[Full-disclosure] AST-2012-012: Asterisk Manager User Unauthorized Shell Access

2012-08-30 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-012 Product Asterisk Summary Asterisk Manager User Unauthorized Shell Access Nature of Advisory Permission Escalation

[Full-disclosure] AST-2012-011: Remote crash vulnerability in voice mail application

2012-07-05 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-011 ProductAsterisk SummaryRemote crash vulnerability in voice mail application Nature of Advisory Denial of Service

[Full-disclosure] AST-2012-010: Possible resource leak on uncompleted re-invite transactions

2012-07-05 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-010 ProductAsterisk SummaryPossible resource leak on uncompleted re-invite transactions

[Full-disclosure] AST-2012-009: Skinny Channel Driver Remote Crash Vulnerability

2012-06-14 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-009 Product Asterisk Summary Skinny Channel Driver Remote Crash Vulnerability Nature of Advisory Denial of Service

[Full-disclosure] AST-2012-008: Skinny Channel Driver Remote Crash Vulnerability

2012-05-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-008 Product Asterisk Summary Skinny Channel Driver Remote Crash Vulnerability Nature of Advisory Denial of Service

[Full-disclosure] AST-2012-007: Remote crash vulnerability in IAX2 channel driver.

2012-05-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-007 ProductAsterisk SummaryRemote crash vulnerability in IAX2 channel driver. Nature of Advisory Remote crash

[Full-disclosure] AST-2012-006: Remote Crash Vulnerability in SIP Channel Driver

2012-04-23 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-006 Product Asterisk Summary Remote Crash Vulnerability in SIP Channel Driver Nature of Advisory Remote Crash

[Full-disclosure] AST-2012-005: Heap Buffer Overflow in Skinny Channel Driver

2012-04-23 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-005 Product Asterisk Summary Heap Buffer Overflow in Skinny Channel Driver Nature of Advisory Exploitable Heap Buffer Overflow

[Full-disclosure] AST-2012-004: Asterisk Manager User Unauthorized Shell Access

2012-04-23 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-004 Product Asterisk Summary Asterisk Manager User Unauthorized Shell Access Nature of Advisory Permission Escalation

[Full-disclosure] AST-2012-003: Stack Buffer Overflow in HTTP Manager

2012-03-15 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-003 Product Asterisk Summary Stack Buffer Overflow in HTTP Manager Nature of Advisory Exploitable Stack Buffer Overflow

[Full-disclosure] AST-2012-002: Remote Crash Vulnerability in Milliwatt Application

2012-03-15 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-002 ProductAsterisk SummaryRemote Crash Vulnerability in Milliwatt Application Nature of Advisory Exploitable Stack Buffer Overflow with locally

AST-2011-014: Remote crash possibility with SIP and the “automon” feature enabled

2011-12-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-014 ProductAsterisk SummaryRemote crash possibility with SIP and the "automon" feature enabled

[Full-disclosure] AST-2011-013: Possible remote enumeration of SIP endpoints with differing NAT settings

2011-12-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-013 ProductAsterisk SummaryPossible remote enumeration of SIP endpoints with differing NAT settings

[Full-disclosure] AST-2011-012: Remote crash vulnerability in SIP channel driver

2011-10-17 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-012 Product Asterisk Summary Remote crash vulnerability in SIP channel driver Nature of Advisory Remote crash

[Full-disclosure] AST-2011-011: Possible enumeration of SIP users due to differing authentication responses

2011-06-28 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-011 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2011-006: Asterisk Manager User Shell Access

2011-04-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-006 ProductAsterisk SummaryAsterisk Manager User Shell Access Nature of Advisory Permission Escalation

[Full-disclosure] AST-2011-005: File Descriptor Resource Exhaustion

2011-04-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-005 Product Asterisk Summary File Descriptor Resource Exhaustion Nature of Advisory Denial of Service

[Full-disclosure] AST-2011-004:

2011-03-16 Thread Asterisk Security Team
ProductAsterisk SummaryRemote crash vulnerability in TCP/TLS server Nature of Advisory Denial of Service Susceptibility Remote Unauthenticated Sessions

[Full-disclosure] AST-2011-003:

2011-03-16 Thread Asterisk Security Team
ProductAsterisk SummaryResource exhaustion in Asterisk Manager Interface Nature of Advisory Denial of Service Susceptibility Remote Unauthenticated Sessions if manag

[Full-disclosure] AST-2011-002: Multiple array overflow and crash vulnerabilities in UDPTL code

2011-02-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-002 Product Asterisk Summary Multiple array overflow and crash vulnerabilities in UDPTL code

[Full-disclosure] AST-2011-001: Stack buffer overflow in SIP channel driver

2011-01-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2011-001 ProductAsterisk SummaryStack buffer overflow in SIP channel driver Nature of Advisory Exploitable Stack Buffer Overflow

[Full-disclosure] AST-2010-003: Invalid parsing of ACL rules can compromise security

2010-02-25 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2010-003 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2010-002: Dialplan injection vulnerability

2010-02-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2010-002 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2010-001: T.38 Remote Crash Vulnerability

2010-02-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2010-001 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2009-010: RTP Remote Crash Vulnerability

2009-11-30 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-010 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2009-009: Cross-site AJAX request vulnerability

2009-11-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-009 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2009-008: SIP responses expose valid usernames

2009-11-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-008 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2009-007: ACL not respected on SIP INVITE

2009-10-26 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-007 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2009-006: IAX2 Call Number Resource Exhaustion

2009-09-03 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-006 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2009-005: Remote Crash Vulnerability in SIP channel driver

2009-08-11 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-005 ++ | Product | Asterisk | |-+--|

[Full-disclosure] AST-2009-004: Remote Crash Vulnerability in RTP stack

2009-08-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-004 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2009-003: SIP responses expose valid usernames

2009-04-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-003 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2009-002: Remote Crash Vulnerability in SIP channel driver

2009-03-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-002 ++ | Product | Asterisk | |-+--|

[Full-disclosure] AST-2009-001: Information leak in IAX2 authentication

2009-01-08 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2009-001 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2008-012: Remote crash vulnerability in IAX2

2008-12-10 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-012 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2008-011: Traffic amplification in IAX2 firmware provisioning system

2008-07-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-011 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2008-010: Asterisk IAX 'POKE' resource exhaustion

2008-07-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-010 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2008-009: AST-2008-007 Cryptographic keys generated by OpenSSL on Debian-based systems compromised

2008-06-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-009 ++ | Product | Asterisk-Addons | |+---|

[Full-disclosure] AST-2008-009: (Corrected subject) Remote crash vulnerability in ooh323 channel driver

2008-06-04 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-009 ++ | Product | Asterisk-Addons | |+---|

[Full-disclosure] AST-2008-008: Remote Crash Vulnerability in SIP channel driver when run in pedantic mode

2008-06-03 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-008 ++ | Product | Asterisk | |+---|

[Full-disclosure] /home/putnopvut/asa/AST-2008-007/AST-2008-007: AST-2008-007 Cryptographic keys generated by OpenSSL on Debian-based systems compromised

2008-05-22 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-007 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2008-002: Two buffer overflows in RTP Codec Payload Handling

2008-03-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-002 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2008-003: Unauthenticated calls allowed from SIP channel driver

2008-03-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-003 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2008-005: HTTP Manager ID is predictable

2008-03-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-005 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2008-004: Format String Vulnerability in Logger and Manager

2008-03-18 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-004 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2008-001: Crash from transfer using BYE with Also header

2008-01-02 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-001 ++ | Product | Asterisk | |-+---

[Full-disclosure] AST-2007-025 - SQL Injection issue in res_config_pgsql

2007-11-30 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-025 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2007-026 - SQL Injection issue in cdr_pgsql

2007-11-30 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-026 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2007-026 - SQL Injection issue in cdr_pgsql

2007-11-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-026 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2007-025 - SQL Injection issue in res_config_pgsql

2007-11-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-025 ++ | Product| Asterisk| |--+-|

[Full-disclosure] AST-2007-023 - SQL Injection Vulnerabilty in cdr_addon_mysql

2007-10-16 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-023 ++ | Product | Asterisk-Addons | |+---|

[Full-disclosure] AST-2007-021: Crash from invalid/corrupted MIME bodies when using voicemail with IMAP storage

2007-08-24 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-021 ++ | Product | Asterisk | |+---|

[Full-disclosure] AST-2007-020: Resource Exhaustion Vulnerability in Asterisk SIP channel driver

2007-08-21 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-020 ++ | Product | Asterisk | |+---|