CVE-2007-2294
Publication date 26 April 2007
Last updated 24 July 2024
Ubuntu priority
The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 authentication to authenticate a user that does not have a password defined in manager.conf, resulting in a NULL pointer dereference.
Status
Package | Ubuntu Release | Status |
---|---|---|
asterisk | 9.10 karmic |
Fixed 1:1.4.3dfsg-1
|
9.04 jaunty |
Fixed 1:1.4.3dfsg-1
|
|
8.10 intrepid |
Fixed 1:1.4.3dfsg-1
|
|
8.04 LTS hardy |
Fixed 1:1.4.3dfsg-1
|
|
7.10 gutsy |
Fixed 1:1.4.3dfsg-1
|
|
7.04 feisty |
Fixed 1.2.16~dfsg-1ubuntu3.1
|
|
6.10 edgy |
Fixed 1.2.12.1.dfsg-1ubuntu1.4
|
|
6.06 LTS dapper | Ignored end of life |