CVE-2008-5558

Publication date 17 December 2008

Last updated 24 July 2024


Ubuntu priority

Description

Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts involving (1) an unknown user or (2) a user using hostname matching.

Read the notes from the security team

Status

Package Ubuntu Release Status
asterisk 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper Ignored end of life

Notes


mdeslaur

As per debian bug, 1.4.x is not affected Dapper may be affected if we fix CVE-2007-6430